Web Application Security

Solution Search:
Move Web Application Security Testing into Your Development Cycle by IBM
paper focuses on the role developers can play in solving Web application security issues, and it details how IBM Rational® AppScan® Developer Edition software can enable them to do so. Web application security issues are an imminent and growing threat. Caused primarily by security bugs in an application's code, Web application security vulnerabilities can allow an online banking client to see another client's data. They can let hackers run queries on an application's back-end...
Web Application Security - How to Minimise Prevalent Risk of Attacks by Qualys
to minimise vulnerabilities in web applications. A guide to web application security outlines typical web application vulnerabilities and provides a comparison of web application vulnerability detection options.

Vulnerabilities in web applications are now the largest vector of enterprise security attacks. Stories about exploits that compromise sensitive data frequently mention culprits such as "cross-site scripting," "SQL injection," and "buffer overflow." Vulnerabilities like these fall...

Web Application Firewalls: Patching, SDLC Key for Security, Compliance by Symantec Corporation
lifecycle (SDLC), are playing an essential role in web application security and compliance. See how you can achieve a strategic, defense-in-depth approach to enterprise security by reading on now.

Web applications are among the most vulnerable parts of the enterprise, and web application defense is quickly becoming a top concern for today’s organizations. Security administrators everywhere are beginning to look at web application firewalls (WAFs) to help meet their security and compliance...

Web Application Security for a Smarter Planet by IBM
As threats to Web applications continue to grow, IBM offers Web application security for a smarter planet—integrated, end-to-end security to build secure Web applications, run secure Web applications and protect SOA environments.

With more websites integrating dynamic web applications, service oriented architectures, online transacting options and other complex Web 2.0 technologies, effective security systems are fast becoming top priority for federal agencies. Read this IBM white paper and find...

State of Software Security Report by Veracode, Inc.
of supplier in the software supply chain and then explores application security by language, industry, and by application type across both web and non-web applications.

New in Volume 2 are data from third-party assessments, the first inclusion of PHP and ColdFusion applications, a comparison of static binary, dynamic, and manual testing effectiveness, and additional analytics on Financial industry applications.

Web Application Security: How to Minimize the Risk of Attacks by Qualys
This informative white paper outlines the importance of Web application security. With over 55 percent of vulnerabilities in 2010 resulting in attacks, a solution is necessary. Learn more about the different types of Web application vulnerabilities as well as how to detect vulnerabilities more efficiently.

While web applications can provide many benefits, they are also the largest source of enterprise security attacks – accounting for over 55 percent of vulnerabilities in 2010, according to a...

Understanding Web Application Security Challenges by IBM
discusses an approach for improving your organization's Web application security. As businesses grow increasingly dependent upon Web applications, these complex entities grow more difficult to secure. Most companies equip their Web sites with firewalls, Secure Sockets Layer (SSL), and network and host security, but the majority of attacks are on applications themselves - and these technologies cannot prevent them.

This paper explains what you can do to help protect your organization,...
Web-Facing Applications: Mitigating Likely Web Application Threats by Symantec Corporation
E-Guide, learn how the increased use of business-centric Web applications has spawned alarming new information security threats. Also inside, uncover tips, tricks, and best practices for making your Web apps more secure – read on to get started.

The Internet has allowed for an unprecedented degree of interactivity between organizations and their customers via Web applications, blogs, and forums, yet the rise of business-centric Web interactivity has also spawned new and

...
Eradicate Cross-Site Scripting by Veracode, Inc.
help with remediation.

Application development and application security teams and practitioners can, in fact, begin automated testing and detection of XSS vulnerabilities immediately, using a Free Service from Veracode. In this white paper, you’ll learn more about the cross-site scripting threat, how automated code testing can help detect and remediate it, and the free service that will help energize your application security program.

E-Guide: Preventing and detecting security vulnerabilities in Web applications by BlueCoat
The extent of fundamental security flaws in most applications often requires a re-architecture, but there are some secondary measures information security teams can take to safeguard faulty applications. This expert tip maps out the steps security professionals should take to lock down their Web applications.

The extent of fundamental security flaws in most applications often requires a re-architecture, but there are some secondary measures...

How web application vulnerability assessment tools can improve enterprise security by IBM
This white paper outlines a web application vulnerability assessment tool that will help you to identify and remediate vulnerabilities earlier in the software development lifecycle.

Security has become a foremost priority for many IT decision makers as web-based applications can compromise the overall security of an organization. These vulnerabilities can enable hackers to access confidential company information or customer data which could result...

Practical Approaches for Securing Web Applications across the Software Delivery Lifecycle by IBM
integrating security and risk management throughout the web application software development lifecycle.

Enterprises understand the importance of securing web applications to protect critical corporate and customer data. What many don’t understand, is how to implement a robust process for integrating security and risk management throughout the web application software development lifecycle.

Securing the web application lifecycle does not have to mean slowing it down. When...

Avocent Accelerates Critical Applications over WAN While Ensuring Distributed Web Security at Branch Offices by BlueCoat
of key business applications and provide decentralized Web security and control for their branch offices. View this case study to learn how they were able to meet both needs with just one solution.

IT infrastructure management solutions provider, Avocent Corporation, needed to accomplish two critical tasks: Improve performance of key business applications and provide decentralized Web security and control for their branch offices.

View this case study to learn how they...

Ensuring the security of your mobile business intelligence by IBM
from their mobile devices, whether from a native application or the web, that security measures are in place to ensure their BI data is protected and safe from hackers or if a device is ever lost or stolen. Read to find strategies on how to best secure BI on mobile devices.

One of the biggest concerns organizations have when it comes to adopting mobile business intelligence (BI) is security.

Organizations need to know that when their employees access BI applications from their mobile

...
PCI DSS Success: Archiving Compliance and Increasing Web Application Availability by Citrix
requirements is absolutely critical. And with the newest security requirements taking effect June 30, 2008, you need to move quickly.

Here's some help: a complimentary guide which helps you achieve the latest PCI DSS security mandates. You'll get practical insight to ensure your success, including:

  • The newest security measures you must have in place by June 30, 2008
  • 6 key recommendations to ensure ongoing PCI DSS compliance
  • How to deploy a security solution that also
...
Resin Application Server Java EE 6 Web Profile by Caucho Technology
standards-based runtime that focuses on ease-of-use for web application development. Indeed, Resin is the only major application server solely focused on the Web Profile.

Next Generation Web Application Firewalls (NG-WAF) by Imperva
Imperva's vision for the next generation of WAFs. It details Web application security problems and solutions today, and gives perspectives on the future.

This paper describes Imperva's vision for the next generation of WAFs. It details Web application security problems and solutions today, and gives perspectives on the future. While this paper is not product specific, areas where Imperva SecureSphere currently provides NG-WAF capabilities such as anti-automation, and adaptive threat response are...

Presentation Transcript: Client-Side Security Issues - The Twilight Zone of Web Security by IBM
types of JavaScript client-side issues that exist in today’s Web applications, their prevalence on the internet and how to locate and fix them.

Client-side vulnerabilities in JavaScript are difficult to locate and require deep knowledge of JavaScript, as well as the ability to perform code review for HTML pages and JavaScript files. This presentation transcript discusses the various types of JavaScript client-side issues that exist in Web applications, their prevalence on the...

Information Security Magazine: March 2009 - Sky-High Risk? by Information Security Magazine
ways monitor and manage Web 2.0 usage within your company; Web Application Firewalls - How to choose and implement the right WAF for your company; and much more.

This month's issue of Information Security focuses on risk management. The cover story, "How to Secure Cloud Computing", discusses emerging on-demand computing services. Cloud computing can create great cost savings for both large and small businesses, but what does it cost in terms of security and compliance set-backs? We'll also go into...

Secure Mobile access to Corporate Applications by F5 Networks
a strategy that balances bring-your-own-device (BYOD) with security, giving your mobile workforce the access to corporate web apps that they need without sacrificing security in the process.

The bring-your-own-device (BYOD) trend has drastic implications for organizations everywhere. As more and more employees choose to conduct business from personally-owned mobile devices, IT is losing control over the enterprise. BYOD isn’t going away – but empowering your mobile workforce can't come...

CORE IMPACT Pro V10 by Core Security Technologies
Please join Core Security for a live demonstration of CORE IMPACT Pro, the most comprehensive product for performing security assurance testing on an organization’s network systems, endpoint systems, end users and web applications. Product Type: Penetration Testing

IT Problem:
Proactive penetration testing for effective risk management.

IT Download Description:
Please join Core Security for a live demonstration of CORE IMPACT Pro, the most...

PCI DSS Compliance with Riverbed Stingray Traffic Manager and Stingray Application Firewall by Riverbed Technology, Inc.
with many parts of the PCI DSS specification, notably the web application firewall (WAF) requirements of section 6.6.

The Payment Card Industry Data Security Standard (PCI DSS) is a mandatory requirement for any merchant that handles confidential cardholder data, including businesses that take orders online. This detailed white paper describes how the Riverbed® Stingray™ Traffic Manager and Stingray Application Firewall Module can help you with many parts of the PCI DSS specification, most...

When Web 2.0 Becomes Security Risk 2.0 by Kaspersky Lab
vulnerabilities in files, widgets and social sites, employ web application firewalls and use content filtering to mitigate risk. Cyber-criminals are targeting web surfers on popular social networking sites like Facebook, LinkedIn and MySpace. This security brief discusses how to protect your business from "trusted" friends turned hostile hackers, pinpoint vulnerabilities in files, widgets and social sites, employ web application firewalls and use content filtering to mitigate risk...
Integrated Approaches to Optimizing Security in the Financial Sector by F5 Networks
integrated risk management solution that uses network and web application firewall security can help your financial institution prevent losses, operational disruption, brand damage, and data loss.

An increasing number of cyberattacks have been targeting financial services companies, attacks which are only growing in complexity, frequency, and sophistication.

This white paper details how an integrated risk management solution that uses network and web application firewall security...

Related Articles
Massive Epsilon email breach could lead to email attacks, spam by Robert Westervelt, News Director
Walgreens and the Home Shopping Network. The company announced last Friday that a breach may have exposed the names and email addresses of thousands of people... More...
Apr 5, 2011
Amplidata launches object storage system; more SNW Spring 2011 news by Sonia R. Lelii, Senior News Writer
dual Gigabit Ethernet (GbE) network interfaces and is powered by Intel Atom processors. The controller node sits on the front end and is powered by dual, six... More...
Apr 5, 2011
RSA SecurID breach began with spear phishing attack by Robert Westervelt, News Director
surfed on the victims, mapped the network and the resources, and started looking for a path to the coveted assets they desired, Rivner said.

"The attackers first... More...

Apr 4, 2011
Related Q&A
Network management shortcuts -- Tools and frameworks by Amy Kucharik, Site Editor
company may make use of outsourced network administration. Most of all, network troubleshooting in small networks is unnecessarily complicated when that network lacks the... More...
Author dissects inclusion of IPsec in Linux 2.6 kernel by Jan Stafford, Editor
what is in effect their own private network, using any physical network system such as the Internet. Friendly systems can also be arranged for encrypted... More...
A practical guide for SAP Basis Administrators by Matt Danielsson, Assistant Editor
to share my knowledge on R/3 Basis administration and help those who have encountered frustration and confusion in their journey through the SAP R/3 Technical... More...
New factors may drive IPv6 adoption by Jim Rendon, News Writer
Dual stacks of devices complicate network administration and troubleshooting.
Are there any dramatic benefits to IPv6 that may compel a business to make the leap?

IPv6 has IPsec... More...
Notebook Reviews

HP Pavillion dv5t Review

The dv5t features an Intel Core 2 Duo Processor, up to 4096MB DDR2 System Memory, NVIDIA GeForce Go graphics available and 15.4" diagonal WXGA BrightView Widescreen.
Find HP Coupon Codes

Dell Inspiron 1525 Review

The Inspiron 1525 is a Core 2 Duo powered 15.4" screen notebook from Dell. The Inspiron 1525 has Intel X3100 integrated graphics, an Intel Core 2 Duo processor and a thinner and lighter form factor than the previous Inspiron 1520.
Find Dell Coupon Codes

Dell Deals, HP Deals, Lenovo Deals, All Laptop Deals