Thursday, December 18, 2008

Important Web Security Links

http://technet.microsoft.com/en-us/security/default.aspx
http://www.microsoft.com/security/default.mspx
http://technet.microsoft.com/hi-in/security/cc297185(en-us).aspx
http://msdn.microsoft.com/en-us/library/ms998325.aspx
http://www.asp.net/learn/whitepapers/

http://msdn.microsoft.com/hi-in/library/ms995349(en-us).aspx


Locate Assemblies by Using DEVPATH

http://msdn.microsoft.com/en-us/library/cskzh7h6.aspx

Specifying an Assembly's Location

http://msdn.microsoft.com/en-us/library/4191fzwb.aspx


Disable Concurrent Garbage Collection

http://msdn.microsoft.com/en-us/library/at1stbec.aspx


Security Policy Management

http://msdn.microsoft.com/en-us/library/c1k0eed6.aspx


ASP.NET whitepapers

http://www.asp.net/learn/whitepapers/

Web Goats

Download books

http://www.lulu.com/content/1416452


Session Fixation

http://www.acros.si/papers/session_fixation.pdf


Authentication Diagram

http://cwe.mitre.org/documents/sources/WASCThreatClassificationTaxonomyGraphic.pdf


New Web Application Attacks and Protection.

http://www.nethemba.com/new_web_attacks-nethemba.pdf


CSRF

http://www.gnucitizen.org/blog/cross-site-request-forgery/


Http Response splitting.

http://www.securiteam.com/securityreviews/5WP0E2KFGK.html

Google Search Operators

http://www.googleguide.com/advanced_operators.html


Format String attack

http://muse.linuxmafia.org/lost+found/format-string-attacks.pdf


Secure SDLC

https://buildsecurityin.us-cert.gov/daisy/bsi/articles/knowledge/sdlc/326-BSI.html

Application Security Firewall - ModSecurity

https://www.owasp.org/images/7/78/OWASP_NYC_2008-Web_Intrusion_Detection_with_ModSecurity.pdf

ASP.NET Forums

http://forums.asp.net/

The economics of Ecommerce

http://www.conerlyconsulting.com/ecommerce.pdf

Rolling Your Own Website Administration Tool

http://aspnet.4guysfromrolla.com/articles/052307-1.aspx

No comments: