public marks

PUBLIC MARKS with tags clevermarks & security

2010

Une faille sur la pseudo-classe :visited - Alsacréations

by claire_
La toute dernière génération de navigateurs (Firefox 3.7, Chrome 5, Safari 4.0.5) vient subitement de considérablement restreindre l’éventail des propriétés CSS applicables à la pseudo-classe :visited, vieille comme le Web et désignant un lien que l’on a déjà suivi. Les seules propriétés dorénavant tolérées sur cet élément se limitent à la définition des couleurs (color, background-color, border-color, outline-color, column-rule-color, fill, et stroke).

Drupal site organization, monitoring, management and best practices: Droptor

by claire_
Finally, an easy way to keep all of your Drupal sites secure, tuned and organized.

2009

OAuth-OpenID: You’re Barking Up the Wrong Tree if you Think They’re the Same Thing

by holyver (via)
OAuth, OpenID…they sound like the same thing and they kind of do vaguely similar things But I’m here to tell you, OAuth is not Open ID. They have a different purpose. I’ve been playing around with OAuth a bit in the past couple weeks and have a grip on what it’s aiming to do and what it’s not aiming to do. To start with, here’s what OAuth does have in common with Open ID

2008

Gnu Privacy Guard tutorial, part 1 || kuro5hin.org

by mbertier
This article will be a tutorial overview of using Gnu Privacy Guard to generate your own public keys. It will also discuss some of the principles of public key systems.

Automated security updates in Debian « N0T a Blog

by mbertier & 3 others (via)
Subscribing to the security mailing lists is a must for every sysadmin, but who has the stamina and the determination to actually read them, and then analyze the impact of both the threat and the proposed fix? A more casual user with no life-or-death-critical servers would happily settle for a solution that would download and install the security patches automatically. As always in Linux, there is more than one way of achieving this. cron-apt works for me.

SignServer 3.0 - Home

by mbertier (via)
The SignServer is an application framework performing cryptographic operations for other applications. It's intended to be used in environments where keys are supposed to be protected in hardware but there isn't possible to connect such hardware to existing enterprise applications or where the operations are considered extra sensitive so the hardware have to protected more carefully. Another usage is to provide a simplified method to provide signatures in different application managed from one location in the company.

Welcome to REMO | REMO - Rule Editor for ModSecurity

by mbertier (via)
This is a project to build a graphical rule editor for ModSecurity with a positive/whitelist approach.

Jeremiah Grossman: New Flash XSS technique (thousands of websites at risk)

by mbertier (via)
- Move Flash files to a secondary domain – just as is recommended with all third-party / user generated / untrusted content. This solution has promise as it sets up some domain barriers in the event a vulnerable Flash file shows up linked from your website.

2007

Suhosin 0.9.21 - XSS Protection - PHP Security Blog

by mbertier
It has been a very long time since the last Suhosin extension has been released, but today this has changed with the release of Suhosin 0.9.21. Among the changes are two new features that will protect applications that put too much trust into the SERVER variables from several XSS (and SQL injection) attacks. These features are suhosin.server.strip and suhosin.server.encode.

PHPIDS » Web Application Security 2.0 » Index

by mbertier & 1 other (via)
PHPIDS (PHP-Intrusion Detection System) is a simple to use, well structured, fast and state-of-the-art security layer for your PHP based web application. The IDS neither strips, sanitizes nor filters any malicious input, it simply recognizes when an attacker tries to break your site and reacts in exactly the way you want it to. Based on a set of approved and heavily tested filter rules any attack is given a numerical impact rating which makes it easy to decide what kind of action should follow the hacking attempt. This could range from simple logging to sending out an emergency mail to the development team, displaying a warning message for the attacker or even ending the user’s session.

GreenSQL - Open Source Database Firewall Solution

by mbertier & 4 others
GreenSQL is an Open Source database firewall used to protect databases from SQL injection attacks. GreenSQL works in a proxy mode and has built in support for MySQL. The logic is based on evaluation of SQL commands using a risk scoring matrix as well as blocking known db administrative commands (DROP, CREATE, etc). GreenSQL is distributed under the GPL license

The Usability of Passwords - Baekdal.com

by mbertier & 5 others (via)
Passwords can be made both highly secure and user-friendly.

HTML Purifier - Filter your HTML the standards-compliant way!

by mbertier & 19 others
HTML Purifier is a standards-compliant HTML filter library written in PHP. HTML Purifier will not only remove all malicious code (better known as XSS) with a thoroughly audited, secure yet permissive whitelist, it will also make sure your documents are standards compliant, something only achievable with a comprehensive knowledge of W3C's specifications.

Forrester narrows list of specs for Web services

by nhoizey
"The place to really watch, if you're a conservative watcher and you don't want to watch much in the industry about these emerging specifications is WS-I," he said. "It's putting together answers to technical questions that people need answered if they want things to work together for Web services interoperability."

PUBLIC TAGS related to tag clevermarks

apache +   attachment +   authentication +   basic +   bestpractices +   browser +   css +   database +   debian +   dev +   drupal +   faq +   flash +   groupe:clever age +   groupe:clever-age +   howto +   introduction +   module +   mysql +   oAuth +   openid +   php +   php5 +   pki +   profile +   security +   sécurité +   soap +   standards +   tools +   usability +   web service +   webdev +   ws-* +   ws-i +   ws-security +   wsdl +  

Active users

claire_
last mark : 17/05/2010 14:29

holyver
last mark : 23/06/2009 20:42

mbertier
last mark : 20/02/2008 10:28

nhoizey
last mark : 12/02/2007 15:36