All-in-One Guides:Web application security -- How to prevent attacks
Web application security -- How to prevent attacks
Web application security tools and services
In many cases, tools can help detect security flaws and advise on how to fix them. Here's a look at some of the tools available -- free and paid.
-
Protect Web site passwords from targeted password crackers
Tip - The criteria included in your password policy could work against you and make it easier for password cracking tools to break user passwords. Anurag Agarwal explains how that could happen to your Web application and steps to take to avoid such attacks.
-
What to look for in a Web application security testing tool
Tip - If you do a lot of Web application security scanning, any testing tool you use must have these features, says security expert Kevin Beaver. They will save you lots of time and effort and will increase the number of valid vulnerabilities found.
-
Obfuscation tools and application security
Ask the Expert - Obfuscator tools are quite different from other application security tools. Expert Brad Arkin lays out the basics of code obfuscation.
-
Code analysis: Which tool is right for you?
Ask the Expert - Code scanners are excellent application security tools. Expert Brad Arkin explains which features security professionals should consider when choosing a code analysis tool.
-
BMC uses source code analysis to improve software line
20 Nov 2007
Article - BMC Software uses Klocwork's K7 automated source code analysis tool to help it improve the quality and reliability of its enterprise software lines.
-
Using fuzzer tools to find vulnerabilities
Ask the Expert - Fuzzers are excellent tools for finding vulnerabilities in your software. They can be used legitimately by a developer or maliciously by a hacker. Expert Brad Arkin explains how to use fuzzers in order to enhance security.
-
Vulnerability scanners: The automation option
Ask the Expert - Automatic vulnerability scanners can help protect you applications from exploits. Expert Brad Arkin explains how these security tools work.
-
HP software security suite treats vulnerabilities as defects
28 May 2008
Article - HP announced the first major updates to HP Application Security Center since its purchase last year of software security specialist SPI Dynamics. The suite, now available as SaaS, supports a process that handles security vulnerabilities as just another...
-
Enhanced application protection in Dotfuscator Professional 4.3
17 Mar 2008
Article - Dotfuscator Professional 4.3 has enhanced application protection and heuristics that automatically extend to applications that use advanced Microsoft .NET Framework components.
-
Ruby on Rails security audit service available
09 Jun 2008
Article - Relevance, a Ruby on Rails software development practice, recently launched its Rails Security Audit. The service helps companies identify security vulnerabilities in Rails apps.