Posts in InfoSec

Saturday, September 24, 2005

Bad Behavior

I’ve been getting a lot of comment spam lately, so I’ve installed Bad Behavior, which takes a different approach to spam blocking:

Bad Behavior was designed and built by watching actual spambots which harvested email addresses, posted comment spam, and used fake referrers. By logging their entire HTTP requests and comparing them to HTTP requests of legitimate users, it is possible to detect most spambots.

Let me know if you have any problems. I’ll post some impressions after I’ve used it a bit.

Posted in InfoSec, PHP by funkatron on 09/24 at 08:21 AM

Wednesday, September 07, 2005

Real-World Web Application Security

I did a seminar today on web app security. I’ve got the slides up over here:

http://homes.cerias.purdue.edu/~coj/

The video should be back to us next week. I’ll post it then.

I wish I had more time. I had seen these seminars go 1:20 before, but I guess this year they have another class in the same room, so I only had 50 minutes firm. I really had to rush through everything. It was pretty broad, and a lot more depth could have been given.

Posted in InfoSec, The Web Problem by funkatron on 09/07 at 05:36 PM

Tuesday, July 19, 2005

Ow.

Posted in InfoSec, The Web Problem by funkatron on 07/19 at 12:11 PM

Tuesday, July 05, 2005

This is too great

Blake Ross on Firefox and Beyond » The new Firefox tag line

“Firefox?” The Rabbi stops and thinks for a minute, rubbing his beard. “Ah yes! The one that blocks all the schmutz.”
Posted in InfoSec, The Web Problem by funkatron on 07/05 at 08:48 AM

Wednesday, June 29, 2005

WordPress 1.5.1.3 Available

WordPress 1.5.1.3 Available:

…an important security issue was brought to our attention which required an update for our users. The problem is not yet public but you should update your blog as soon as possible to 1.5.1.3. If you are unable to do upgrade in the short-term you may protect yourself by deleting the xmlrpc.php file from your WordPress directory.

Obviously if you use the XML-RPC interface (for posting from client apps and external services like flickr), deleting the xmlrpc.php file is gonna be less than appealing.

Posted in General, InfoSec, PHP by funkatron on 06/29 at 08:28 AM
Page 9 of 11 pages « First  <  7 8 9 10 11 >