ICT Security-Sécurité PC et Internet
87.1K views | +0 today
Follow
ICT Security-Sécurité PC et Internet
ICT Security + Privacy + Piracy + Data Protection - Censorship - Des cours et infos gratuites sur la"Sécurité PC et Internet" pour usage non-commercial... (FR, EN+DE)...
Curated by Gust MEES
Your new post is loading...
Your new post is loading...
Scooped by Gust MEES
Scoop.it!

Imperva analyzes LulzSec’s attack tool

Imperva analyzes LulzSec’s attack tool | ICT Security-Sécurité PC et Internet | Scoop.it
In its latest Hacker Intelligence Initiative report, Imperva analyzes remote and local file inclusion (RFI/LFI) attacks as favored by LulzSec.

 

===> Imperva suggests a number of ways to mitigate against RFI/LFI attacks. These include finding your own vulnerabilities using the same methods as the hackers: dorking (otherwise known as ‘Google hacking’, which uses the search engines to find hints of possible vulnerabilities); and the use of both commercial and free vulnerability scanners. <===

 

Also useful would be a web application firewall (WAF) and blacklisting known attacks IPs. The report also notes that the application code can be written to exclude RFI attacks, so detailed code review is advisable.

No comment yet.
Scooped by Gust MEES
Scoop.it!

Hackers Hacking Hackers - Imperva Data Security Blog

Hackers Hacking Hackers - Imperva Data Security Blog | ICT Security-Sécurité PC et Internet | Scoop.it
"One thing about us wiseguys, the hustle never ends." --Tony Soprano, season 1, episode 5 "College." In January of this year, we blogged about a hacker site that sold admin access to several military, education and government websites.
No comment yet.
Scooped by Gust MEES
Scoop.it!

How to Stop SQL Injection - Imperva Data Security Blog

How to Stop SQL Injection - Imperva Data Security Blog | ICT Security-Sécurité PC et Internet | Scoop.it
On the very last day of 2011, SANS published a story about automated SQL injection attacks affecting 1M plus websites. What will be different with SQL injection in 2012? Nothing. Perhaps more, perhaps some new attack tools.

 

Here's what any firm that has data flowing in web applications should do in order to protect themselves from SQL injection:

...

No comment yet.
Scooped by Gust MEES
Scoop.it!

Toutes les 2 minutes, une application web est attaquée, selon Imperva - Global Security Mag Online

Toutes les 2 minutes, une application web est attaquée, selon Imperva - Global Security Mag Online | ICT Security-Sécurité PC et Internet | Scoop.it
Imperva publie aujourd’hui son rapport sur les attaques d’applications web.
No comment yet.