Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 41 guests and 3 members online
You are here:
Home
Ethical Hacking Discussions and Related Certifications
Web Applications
Web Security Mailing List
EH-Net
May 21, 2013, 10:00:35 AM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Ethical Hacking Discussions and Related Certifications
>
Web Applications
(Moderator:
don
) >
Web Security Mailing List
Pages: [
1
]
2
Go Down
« previous
next »
Print
Author
Topic: Web Security Mailing List (Read 7899 times)
0 Members and 1 Guest are viewing this topic.
alucian
Full Member
Offline
Posts: 225
Web Security Mailing List
«
on:
January 14, 2012, 03:20:10 PM »
Hi,
Today I found this information (while reading WAHH2) and I thought to share it with you. You can have free access at the archive at:
http://lists.webappsec.org/pipermail/websecurity_lists.webappsec.org/
"What is The Web Security Mailing List?
The Web Security Mailing List is an open information forum for discussing topics relevant to web security. Topics include, but are not limited to, industry news and technical discussions surrounding web applications, proxies, honeypots, new attack types, methodologies, application firewalls, discoveries, experiences, web servers, application servers, database security, tools, solutions, and others. "
I already found some interesting topics.
Logged
CISSP ISSAP, CISM/A, GWAPT, GCIH, eCPPT, OSWP
MaXe
Hero Member
Offline
Posts: 669
I've just upgraded myself to a cyborg muahahaa!!1
Re: Web Security Mailing List
«
Reply #1 on:
January 14, 2012, 05:05:35 PM »
There's also the Owasp Mailing lists, that occasionally has "good" info too.
The webappsec.org mailing is however, heavily moderated and rarely contains the really cool stuff you would see on less heavily moderated lists. But it's a good list to follow none the less. ~ My personal opinion hehe
Logged
I'm an InterN0T'er
l33t5h@rk
Jr. Member
Offline
Posts: 79
Re: Web Security Mailing List
«
Reply #2 on:
January 14, 2012, 07:32:08 PM »
Quote from: MaXe on January 14, 2012, 05:05:35 PM
There's also the Owasp Mailing lists, that occasionally has "good" info too.
The webappsec.org mailing is however, heavily moderated and rarely contains the really cool stuff you would see on less heavily moderated lists. But it's a good list to follow none the less. ~ My personal opinion hehe
I am a member of OWASP and wanted to give a shout to everyone out there to try to attend meetings (typically free) and check out free OWASP courses/learning materials.
Logged
alucian
Full Member
Offline
Posts: 225
Re: Web Security Mailing List
«
Reply #3 on:
January 14, 2012, 07:49:17 PM »
I am a member of OWASP and wanted to give a shout to everyone out there to try to attend meetings (typically free) and check out free OWASP courses/learning materials.
[/quote]
This courses/learning are offered to the members only, or they are offered to the public?
Logged
CISSP ISSAP, CISM/A, GWAPT, GCIH, eCPPT, OSWP
l33t5h@rk
Jr. Member
Offline
Posts: 79
Re: Web Security Mailing List
«
Reply #4 on:
January 14, 2012, 08:40:40 PM »
Quote from: alucian on January 14, 2012, 07:49:17 PM
This courses/learning are offered to the members only, or they are offered to the public?
Hi Alucian - Don't see that it is restricted, give it a shot:
http://www.owaspa.org/learning_blocks/login/index.php
Logged
MaXe
Hero Member
Offline
Posts: 669
I've just upgraded myself to a cyborg muahahaa!!1
Re: Web Security Mailing List
«
Reply #5 on:
January 14, 2012, 11:51:31 PM »
Quote from: alucian on January 14, 2012, 07:49:17 PM
This courses/learning are offered to the members only, or they are offered to the public?
Some of the live courses does cost money
Well, not the actual courses, but to be a member you have to pay, in order to attend some if not all live courses.
Logged
I'm an InterN0T'er
alucian
Full Member
Offline
Posts: 225
Re: Web Security Mailing List
«
Reply #6 on:
January 14, 2012, 11:59:50 PM »
I think that the access to this courses and the fact that part of the money will go to support some OWASP projects justify the 50$ for membership.
I'll join OWASP as a member.
Thanks!
Logged
CISSP ISSAP, CISM/A, GWAPT, GCIH, eCPPT, OSWP
l33t5h@rk
Jr. Member
Offline
Posts: 79
Re: Web Security Mailing List
«
Reply #7 on:
January 15, 2012, 11:27:13 AM »
Quote from: alucian on January 14, 2012, 11:59:50 PM
I think that the access to this courses and the fact that part of the money will go to support some OWASP projects justify the 50$ for membership.
I'll join OWASP as a member.
Thanks!
Yeah huge value in my opinion, wealth of information for the cost!
Logged
tturner
Sr. Member
Offline
Posts: 432
Re: Web Security Mailing List
«
Reply #8 on:
January 18, 2012, 01:13:58 PM »
Check out your local OWASP chapter at
https://www.owasp.org/index.php/Category:OWASP_Chapter
I run the recently formed OWASP Orlando chapter and we have some amazing speakers lined up for our next meeting. I consistently see world class speakers, the guys who you typically only see at major conferences, speaking at these free events. It's amazing value and part of the reason why I am involved is the huge potential for outreach with non-security developer and sysadmin groups, where we really need it. Even if you don't join as a paying member (although I HIGHLY recommend it) come out to a local chapter meeting, get involved in the discussion and join the party! I don't know of any chapters that charge for attendance to these events and the presentations usually blow other nameless information security groups' vendor shills out of the water.
Shameless plug -
https://www.owasp.org/index.php/Orlando
Logged
Certifications:
CISSP, CISA, GPEN, GWAPT, GAWN, GCIA, GCIH, GSEC, OPSE, CSWAE, CSTP, VCP
WIP: OSWP, GSSP-JAVA, GXPN
Udacity on hold, again. I suck.
http://sentinel24.com/blog
@tonylturner
http://bsidesorlando.org
3xban
Hero Member
Online
Posts: 607
Re: Web Security Mailing List
«
Reply #9 on:
January 18, 2012, 03:16:43 PM »
Out CT OWASP chapter appears to be dead. There is no activity and when you try to sign up you get a bounce back for the list with no response from the chapter president. I was hoping to look for a professional group to meet with every so often to talk geek and Info Sec. Hmm maybe some the chapter needs a jump start.
Logged
Certs: GCWN
(@)Dewser
tturner
Sr. Member
Offline
Posts: 432
Re: Web Security Mailing List
«
Reply #10 on:
January 18, 2012, 03:22:18 PM »
Sounds like an opportunity to get involved!
Logged
Certifications:
CISSP, CISA, GPEN, GWAPT, GAWN, GCIA, GCIH, GSEC, OPSE, CSWAE, CSTP, VCP
WIP: OSWP, GSSP-JAVA, GXPN
Udacity on hold, again. I suck.
http://sentinel24.com/blog
@tonylturner
http://bsidesorlando.org
lorddicranius
Sr. Member
Offline
Posts: 447
Re: Web Security Mailing List
«
Reply #11 on:
January 18, 2012, 03:38:27 PM »
Quote from: 3xban on January 18, 2012, 03:16:43 PM
Out CT OWASP chapter appears to be dead. There is no activity and when you try to sign up you get a bounce back for the list with no response from the chapter president.
I was hoping to look for a professional group to meet with every so often to talk geek and Info Sec.
Hmm maybe some the chapter needs a jump start.
Exactly the reason why I'm looking at local groups as well. It looks like the Portland OWASP chapter is starting to pick up again. I jumped on the mailing list in December right before they had their first meeting in a long time. They've scheduled another for this month, as well as scheduled Kevin Johnson (the SANS instructor) for a meeting on June 11th.
I'm a little hesitant to go because it seems most everybody has coding backgrounds at these meetings (judging by their Linkedin profiles). I don't have any kind of coding background and I'm having one hell of a time trying to pick it up myself. But after taking the eLearnSecurity course, the web app security stuff really piques my interest! One day I'll get the courage to go... haha
Logged
GSEC, eCPPT, Sec+
tturner
Sr. Member
Offline
Posts: 432
Re: Web Security Mailing List
«
Reply #12 on:
January 18, 2012, 04:08:56 PM »
Quote from: lorddicranius on January 18, 2012, 03:38:27 PM
They've scheduled another for this month, as well as scheduled Kevin Johnson (the SANS instructor) for a meeting on June 11th.
I'm a little hesitant to go because it seems most everybody has coding backgrounds at these meetings (judging by their Linkedin profiles). I don't have any kind of coding background and I'm having one hell of a time trying to pick it up myself. But after taking the eLearnSecurity course, the web app security stuff really piques my interest! One day I'll get the courage to go... haha
First off, make sure you see Kevin speak. Kevin is AWESOME!
Secondly, don't be scared. Many of these meetings will have a techie talk and a management level talk. For instance, our next meeting has a talk on OWASP the organization and the culture of the org, where we came from and what the roadmap for 2012 looks like and then a technical talk on effective XSS defenses. I find most presentations are pretty easy to follow and I'm a pretty bad coder. The only way you learn is to immerse yourself.
It's OK to show up and tell folks "I'm a sysadmin who wants to learn more about protecting web and mobile apps" or "I'm just learning how to code so I can more effectively test apps" or "I'm here because my wife is a troll and I don't want to go home". These groups are typically very open to new faces and are just happy to see someone else in their area is thinking about appsec. Just don't be an askhole.
Logged
Certifications:
CISSP, CISA, GPEN, GWAPT, GAWN, GCIA, GCIH, GSEC, OPSE, CSWAE, CSTP, VCP
WIP: OSWP, GSSP-JAVA, GXPN
Udacity on hold, again. I suck.
http://sentinel24.com/blog
@tonylturner
http://bsidesorlando.org
ajohnson
Recruiters
Hero Member
Offline
Posts: 1057
aka dynamik
Re: Web Security Mailing List
«
Reply #13 on:
January 18, 2012, 04:45:07 PM »
I really wish there was a chapter in Baton Rouge, or even NOLA. I emailed them about starting a chapter, but I never got a response. I guess I just have to move.
I've never met Kevin personally, but I just wrapped up an engagement with SecureIdeas, and they did a great job. Kevin didn't do the actual testing, but I was impressed that he personally got on the phone right away during pre-sales and helped scope the engagement, discuss methodology, etc.
Logged
WIP: GCFA |
www.infosiege.net
| @infosiege
The day you stop learning is the day you start becoming obsolete.
hayabusa
Hero Member
Offline
Posts: 1631
Re: Web Security Mailing List
«
Reply #14 on:
November 26, 2012, 08:26:51 AM »
No offense to you, rowleytyrese, as at least your spam DOES follow the VERY 'general' ideas of the threads to which you're posting it.
But can you please stop throwing generic information out to every other thread we have? It's like you see a subject, look up a random 2 lines of related information on a brief google search, and post a reply.
If you're not going to post 'useful' information, truly relevant to the actual conversation and contributing to the actual discussion, please don't reply...
<Edit - I KNOW it's still a spammer, but in trying to be polite...>
«
Last Edit: November 26, 2012, 08:30:45 AM by hayabusa
»
Logged
~ hayabusa ~
"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'
OSCE, OSCP , GPEN, C|EH
Pages: [
1
]
2
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
Programming
: Finished Python Course in Codecademy now what?
(12) by
3xban
Network Pen Testing
: AIX Vulnerability Assessments
(1) by
3xban
General Certification
: CPT Practical Submission
(1) by
UNIX
OSCP - Offensive Security Certified Professional
: Failed my first attempt at the OSCP exam
(94) by
azmatt
Tools
: Social-Engineer Toolkit (SET) Version 5.0 “The Wild West” Released
(2) by
m0wgli
Malware
: EICAR?
(3) by
UKSecurityGuy
Advisories
: HTB23154: Multiple Vulnerabilities in Exponent CMS
(0) by
AndyP
Advisories
: HTB23153: Multiple Vulnerabilities in Jojo CMS
(0) by
AndyP
Advisories
: HTB23151: Cross-Site Request Forgery (CSRF) in UMI.CMS
(0) by
AndyP
Tutorials
: Need guidance
(8) by
r0ckm4n
OSCP - Offensive Security Certified Professional
: Class Scheduled 6/8 - Linux n00b
(7) by
Taemyks
OSCP - Offensive Security Certified Professional
: OSCP exam scheduled
(6) by
gbhat
Incident Response
: LinkedIn Forensics
(0) by
AFENTIS_Forensics
General Certification
: Red Team/Blue Team
(1) by
ajohnson
Career Central
: Starter cert?
(3) by
Grendel
Network Pen Testing
: Beginner Ethical Hacker
(1) by
m0wgli
Web Applications
: Nessus and Nikto
(4) by
Seen
Network Pen Testing
: Cracking salted MD5 hash
(4) by
n37sh@rk
CEH - Certified Ethical Hacker
: Passed my C|EH
(3) by
n37sh@rk
Mass Media
: EC-council hacked, irony at his best?
(0) by
j0rDy
Web Applications
: SQL Injection into an INSERT statement.
(6) by
eyenit0
Network Pen Testing
: Solution for sipXtapi INVITE Message CSeq Field Header Remote Overflow
(1) by
m0wgli
Web Applications
: dns
(2) by
H1t M0nk3y
Other
: BSides Boston
(0) by
3xban
Career Central
: InfoSec in Central, FL
(2) by
tturner
Web Applications
: Web vulnerability scanner
(4) by
H1t M0nk3y
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.