Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Saturday, February 20, 2010

GreenSQL – Open Source Database Firewall Software

GreenSQL is an Open Source database firewall used to protect databases from SQL injection attacks. GreenSQL works as a proxy and has built in support for MySQL. The logic is based on evaluation of SQL commands using a risk scoring matrix as well as blocking known db administrative commands (DROP, CREATE, etc). GreenSQL provides MySQL database security solution. GreenSQL is distributed under the GPL license.














More info here : http://www.greensql.net/

Saturday, November 14, 2009

How to break web software(Video)

What Every Web Programmer Needs To Know About Security

Contains
Foundations of Security
secure design principles
common web application vulnerabilities
an introduction to cryptography
and much more



http://code.google.com/edu/submissions/daswani/index.html

Tuesday, November 3, 2009

Auditing tool for security

Rough Auditing Tool for Security – is an open source tool developed and maintained by Secure Software security engineers
RATS is a tool for scanning C, C++, Perl, PHP and Python source code and flagging common security related programming errors such as buffer overflows and TOCTOU (Time Of Check, Time Of Use) race conditions
http://www.darknet.org.uk/2009/11/rats-rough-auditing-tool-for-security/

Tuesday, September 22, 2009

Monday, September 14, 2009

Graudit – Code Audit Tool Using Grep

Graudit is a simple script and signature sets that allows you to find potential security flaws in source code using the GNU utility grep. It’s comparable to other static analysis applications like RATS, SWAAT and flaw-finder while keeping the technical requirements to a minimum and being very flexible

http://www.darknet.org.uk/2009/09/graudit-code-audit-tool-using-grep/

MySqloit , SQL Injection Takeover Tool For LAMP

MySqloit is a SQL Injection takeover tool focused on LAMP (Linux, Apache, MySQL, PHP) and WAMP (Windows, Apache, MySQL, PHP) platforms. It has the ability to upload and execute metasploit shellcodes through the MySql SQL Injection vulnerabilities.

http://www.darknet.org.uk/2009/09/mysqloit-sql-injection-takeover-tool-for-lamp/