Friday, March 28, 2008

Burp to attack the web site application

99 pounds license
clipped from portswigger.net

Burp Suite is an integrated platform for attacking and testing web
applications. It contains the latest versions of all the Burp tools,
including:

  • Burp Proxy
  • All of the Suite tools are tightly integrated, with numerous
    interfaces designed to facilitate and speed up the process
    of attacking an application.

  • Burp Spider
  • Burp Repeater
  • Burp Intruder
  • Burp Sequencer
  • Burp Decoder
  • Burp Comparer
  •  blog it

    Thursday, March 27, 2008

    State of Private Investigator Licensing

    More clarification with letters from many State ofices
    Computer Forensics and Forensic Accounting Licensing Survey - Results are In!

    Kessler International, the leading forensic accounting, computer forensics and corporate investigations firm announced today the release of the results of a nationwide survey detailing each state’s licensing requirements as a private investigator when practicing forensic accounting or computer forensics. The results of the survey can be found here: http://www.investigation.com/surveymap/surveymap.html

     blog it

    Monday, March 24, 2008

    Exploit-Me with Firefox

    Application vulnerability assessment tool, convenient and easy to use
    clipped from www.darknet.org.uk


    SecurityCompass Exploit-Me - Firefox Web Application Testing Tools

    Exploit-Me is a suite of Firefox web application security testing tools. Exploit-Me tools are designed to be lightweight and easy to use. Instead of using a proxy like many web application testing tools, Exploit-Me integrates directly with Firefox. It currently consists of two tools, one for XSS and one for SQL Injection.

    The Exploit-Me series was originally introduced at the SecTor conference in Toronto. The slides for the presentation are available for download [PDF].

    Currently in their beta release stage, these open source (GPL v3) FireFox plug-ins search through web applications for vulnerable visible and hidden form fields to perform input validation attacks.

     blog it

    Wednesday, March 19, 2008

    Grid computing for trading applications

    What makes more sense than distribute your processing to the grid? Here is an example of Allegro, one of the trading leaders, using the multiple CPU power.
    clipped from www.gridtoday.com
    Allegro Leverages Grid Computing in Trading Software
     blog it

    Friday, March 7, 2008

    A plethora of PaaS options

    A nice overview that puts things in perspective. Also contains links for further reading. The summary of options:

    • Do-it-yourself
    • Managed hosting
    • Cloud computing
    • Cloud IDEs
    • Cloud application builders.
    Enjoy!

    How To Set Up Dynamic DNS for your Amazon EC2 Instance

    Here's a step by step to setting up dynamic dns for you EC2 instance. This is required because EC2 does not have static IPs (yet).

  • First of all, you need a dynamic dns account. You can get one at www.dyndns.com or my personal favorite, www.zoneedit.com.
  • Thursday, March 6, 2008

    Linux tool for forensics use by police

    Can we get this CD and use it in the US?
    clipped from news.zdnet.com
    Australian university students have developed a Linux-based data forensics tool to help police churn through a growing backlog of computer-related criminal investigations.
     blog it