These are the presentation slides from a talk called Threat Modeling Cloud Applications: What You Don't Know Will Hurt You as presented at the OWASP AppSec USA 2011 conference.
ca7ed7c83b5ae0d31004acf587fa92652ec54e92efce0b74f1135654c8dcb0a8
These are the presentation slides from a talk called Behavioral Security Modeling: Eliminating Vulnerabilities by Building Predictable Systems as presented at the OWASP AppSec USA 2011 conference.
e197238567599d0b75f2ed394737152a01c303a4b7cb4c4281a3400ab62c8ee8
These slides are from the Trustwave Global Security Report as presented at the OWASP AppSec USA 2011 conference.
5ab47429503233cf331568f72c8c9012c6a1f774e9d2d77647e5d1519521f3bc
These are the slides from the Ghost of XSS Past, Present, and Future presentation given at the OWASP AppSec USA 2011 conference.
0b66340464b5fd19fc7f01d69d5ed582aa6417b0228f67241d9cd66f22e37f7c
These are the slides from the Web Application Security Payloads presentation given at the OWASP AppSec USA 2011 conference.
96859936ed7fb62fae34893a18ab9599f745d4ee65739eebcab392b9321c6777
Endian UTM Firewall version 2.4.x suffers from multiple cross site scripting vulnerabilities.
2b5c8c7d2d61673edc12f2f3c563cd150550ebabf2d739ff844f94b505eb0fdf
The Joomla Xcomp component suffers from a local file inclusion vulnerability.
cd1de8eea256d03c454e980399eb3314f2b099fd3ff8b51f4574ff1088120184
This tool is a php script that assists in finding vulnerable components in multiple CMS systems.
4d2492d8c0103eb62eed2ed37137e6e97badf00162448c9f8015bfeea67e820e
The Joomla X-Shop component suffers from a remote SQL injection vulnerability.
2a1da2cb26bbc9872537f3fcc9e301d5065173529e8cc82639b4990c4e7ae4ba
Rocketwebco suffers from a remote SQL injection vulnerability.
b613704db62597713098ec961ed4711c009bbfe5e3941917b7416ca915dcba57
Abbott Web Experts suffers from a remote SQL injection vulnerability.
298f5ba26e0615469e8da23938fdddca85a62bb590240905b31865af34d139a1
The Joomla XVS component suffers from a local file inclusion vulnerability.
83568394e1e0d7765b6bb3a1a88a20af2661418d31092da6211c6739a9693a83
360-FAAR Firewall Analysis Audit and Repair is an offline command line perl policy manipulation tool to filter, compare to logs, merge, translate and output firewall commands for new policies, in checkpoint dbedit or screenos commands.
17778d746c8d1ca367879a5888a937c7c262af8d555199cc569f432cf3a5fdc4
Wiki Spot suffers from a cross site scripting vulnerability.
4d2b2779ee8292f917098041a48c19cf8e54bd1d6439bb1e92a49ed8615e3b03
Secunia Security Advisory - Ubuntu has issued an update for libpng. This fixes a vulnerability, which can be exploited by malicious people to potentially compromise an application using the library.
5ec9a42f2ba5def5c4f2c3fc4a64992370ad674d06ff5d050cacd113a77d4eb1
Secunia Security Advisory - SUSE has issued an update for jetty5. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
b2433723b92548a1ad622a1ad839dcf0ee77af6a195d821e5499ed085a7a4a2f
Secunia Security Advisory - Dell SecureWorks has reported a vulnerability in Cisco IronPort Encryption Appliance, which can be exploited by malicious people to conduct cross-site scripting attacks.
d5ed499f5d4dbd3bd82fa2a8e35b386b06abb9d43aaff44a2e6cd07ae084694e
Secunia Security Advisory - Red Hat has issued an update for java-1.6.0-sun. This fixes multiple vulnerabilities, which can be exploited by malicious people to disclose potentially sensitive information, manipulate certain data, cause a DoS (Denial of Service), and compromise a vulnerable system.
207002ae2f81cb07d5396140254807f1d74fb121b4e5c54a9df3c34baf8dbf48
Secunia Security Advisory - Red Hat has issued an update for texlive. This fixes multiple vulnerabilities, which can be exploited by malicious people to compromise a user's system.
1594326abb7ae56ebbc6e46a7551c731b6237aee6083400d27347c8cad1feabf
Secunia Security Advisory - Multiple vulnerabilities have been reported in TeX Live, which can be exploited by malicious people to compromise a user's system.
db0713ce237c4422d7a2b6a7fba68a04b7464b4c2264c1c7b5766503429f0cc7
Secunia Security Advisory - Roger Wemyss has reported a vulnerability in SecureSphere Web Application Firewall, which can be exploited by malicious people to conduct script insertion attacks.
8a96b8510c71baa060bfcb866ee2509dfb771e7c58c13ba040e6fd1b2743af30
Secunia Security Advisory - Two vulnerabilities have been reported in TeX Live, which can be exploited by malicious people to compromise a user's system.
b9d4d85b30893bedc619490def724d895be5bf537465e850dffeaa42939c4673
Secunia Security Advisory - Ubuntu has issued an update for apache2. This fixes two weaknesses and some vulnerabilities, which can be exploited by malicious, local users to bypass certain security restrictions and gain escalated privileges and by malicious people to bypass certain security restrictions, disclose potentially sensitive information, and cause a DoS (Denial of Service).
5cf9e3e76f42fed9e07a54fb876955180d8359013ee7ff7d6dc2e5d22fac09d0
SQL Buddy version 1.3.3 suffers from multiple cross site scripting vulnerabilities.
6c5be0f0aa68bcc647b19be562e63c84f28743bf3a61b5fd2087caee57e029b5
Webgrind version 1.0 suffers from a reflective cross site scripting vulnerability.
00f639df58ba9d61fae513dead87ec2a62f2cdd0588a69395d8e74e4294a8e2c