Archive for May, 2007

ROR Security Blog on a roll

Tuesday, May 29th, 2007

If you're new here, you may want to subscribe to my RSS feed. Thanks for visiting!

Here is an article about input parameters validation framework.  It is just a couple of functions but it works very well and is easy to use.

Enjoy.

P.S.  I will be writing something original soon…stay tuned.

Share and Enjoy: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • DZone
  • Wists
  • BlinkList
  • blogmarks
  • Ma.gnolia
  • NewsVine
  • Slashdot
  • StumbleUpon
  • Technorati

Possible XSS issue with to_json in Rails

Friday, May 25th, 2007

The Ruby on Rails Security Blog has a post about a potential XSS issue with to_json.

Enjoy.

Share and Enjoy: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • DZone
  • Wists
  • BlinkList
  • blogmarks
  • Ma.gnolia
  • NewsVine
  • Slashdot
  • StumbleUpon
  • Technorati

A good article about SQL Injection

Monday, May 21st, 2007

The Ruby on Rails Security blog has a good article about SQL Injection and Ruby on Rails.  Check out the SQL Injection article.

Enjoy.

Share and Enjoy: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • DZone
  • Wists
  • BlinkList
  • blogmarks
  • Ma.gnolia
  • NewsVine
  • Slashdot
  • StumbleUpon
  • Technorati

MyBooksmarts.com 4.0 is released

Thursday, May 17th, 2007

It has taken a lot of hard work but I have finally finished the latest version of MyBooksmarts.com.  It is hard to believe one year and four versions.

Please check it out and let me know what you think.

http://mybooksmarts.com/

Thank you and enjoy.

Share and Enjoy: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • DZone
  • Wists
  • BlinkList
  • blogmarks
  • Ma.gnolia
  • NewsVine
  • Slashdot
  • StumbleUpon
  • Technorati

Article about Penetration Testing

Tuesday, May 15th, 2007

Here is an interesting article by Bruce Schneier about the benefits and issues with penetration testing - “Is Penetration Testing Worth It?”.

I think it makes a lot of sense.  I have been researching what types security testing tools are out there and wondering what is the best way to test for security flaws.

Is it better to take outside approach where you look at the system from an attackers perspective?  Or is it better to look from the inside and use all the information available to identify areas where you may be venerable?

I would think the latter would be better because you have more information to work with.  I think it is better to restrict your attack surface, make a security plan and focus on the top venerabilities like Bruce Schneier suggests.

Share and Enjoy: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • DZone
  • Wists
  • BlinkList
  • blogmarks
  • Ma.gnolia
  • NewsVine
  • Slashdot
  • StumbleUpon
  • Technorati

Post about the uses of Amazon’s SQS

Monday, May 7th, 2007

This is a really great post about the usefulness of Message Bus Architecture and, in particular, SQS.

http://aws.typepad.com/aws/2007/05/sqs_super_queue.html 

Share and Enjoy: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • DZone
  • Wists
  • BlinkList
  • blogmarks
  • Ma.gnolia
  • NewsVine
  • Slashdot
  • StumbleUpon
  • Technorati

Two more great articles from the Ruby on Rails Security Blog

Friday, May 4th, 2007

http://www.rorsecurity.info/2007/05/04/dom-injection-attacks/

http://www.rorsecurity.info/2007/05/04/defeating-input-filters-for-injection/

enjoy! :)

Share and Enjoy: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • DZone
  • Wists
  • BlinkList
  • blogmarks
  • Ma.gnolia
  • NewsVine
  • Slashdot
  • StumbleUpon
  • Technorati
  • About Me

    A little something about you, the author. Nothing lengthy, just an overview.

  • You are currently browsing the Dave Elkins blog archives for May, 2007.

  • Elkinsware

    Take a look at my company site to see the services I offer. Elkinsware

  • Biznik - Business Networking