Threat modeling resources - SearchSoftwareQuality.com

Internet Application Security

  • Jason Huggins demos software testing improvements at STPCon 2011

    Watch this STPCon 2011 video of Jason Huggins of Selenium and Sauce Labs, in which he gives some information about his conference demonstration. He relates software testing improvement ideas to his handmade robot that can play Angry Birds on an iPhon... 

  • Injection attacks -- Knowledge and prevention

    SQL injection is recognized as a major threat to application security, but what about other injection attacks? SPI Dynamics' Caleb Sima dissects these exploits and offers straightforward prevention techniques in this podcast. 

About Internet Application Security

Web and rich Internet application security testing services can be used to detect security issues with Web applications and identify vulnerabilities. These vulnerabilities may be known vulnerabilities in custom off-the-shelf applications, technical vulnerabilities or business logic errors. Technical vulnerabilities include URL manipulation, SQL injection, cross site scripting, back-end authentication, password in memory, session highjacking, buffer overflow, Web server configuration, credential management and clickjacking. Business logic errors include day-to-day threat analysis, unauthorized logins, personal information modification, pricelist modification, unauthorized funds transfer and breach of customer trust.