Article Announcement: Auditing Web Site Authentication, Part Two

From: Marc Fossi (mfossi_at_securityfocus.com)
Date: 05/06/03

  • Next message: Free, Bob: "RE: SuS update's"
    Date: Tue, 6 May 2003 09:25:32 -0600 (MDT)
    To: Focus-MS <focus-ms@securityfocus.com>
    
    

    Auditing Web Site Authentication, Part Two

    By Mark Burnett

    This is the second part of a two-part series discussing a standard audit
    procedure consisting of a list of questions to test Web site
    authentication schemes.

    http://www.securityfocus.com/infocus/1691

    Marc Fossi
    Symantec Corp.
    www.symantec.com

    -----------------------------------------------------------------------------
    FastTrain has your solution for a great CISSP Boot Camp. The industry`s most
    recognized corporate security certification track, provides a comprehensive
    prospectus based upon the core principle concepts of security. This ALL INCLUSIVE curriculum utilizes lectures, case studies and true hands-on utilization
    of pertinent security tools. For a limited time you can enter for a chance
    to win one of the latest technological innovations, the SEGWAY HT.
    Log onto http://www.securityfocus.com/FastTrain-focus-ms
    ------------------------------------------------------------------------------


  • Next message: Free, Bob: "RE: SuS update's"

    Relevant Pages

    • SecurityFocus Article Announcment
      ... Auditing Web Site Authentication, Part Two ... By Mark Burnett ... prospectus based upon the core principle concepts of security. ...
      (Security-Basics)
    • [NT] Vulnerability in HTML Help Allows Code Execution (MS05-001)
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Get your security news from a reliable source. ... * Microsoft Windows XP Service Pack 1 and Microsoft Windows XP Service ...
      (Securiteam)
    • [NT] Microsoft JScript Remote Code Execution (MS06-023)
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Get your security news from a reliable source. ... There is a remote code execution vulnerability in JScript. ... Configure Internet Explorer to prompt before running Active Scripting ...
      (Securiteam)
    • [NT] Cumulative Security Update for Internet Explorer (MS05-052)
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Get your security news from a reliable source. ... A remote code execution vulnerability exists in the way Internet Explorer ...
      (Securiteam)
    • [NT] Vulnerability in Microsoft XML Core Services Could Allow Remote Code Execution (MS07-042)
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Get your security news from a reliable source. ... Vulnerability in Microsoft XML Core Services Could Allow Remote Code ... mode sets the security level for the Internet zone to High. ...
      (Securiteam)