Skip to main content

Posts

Showing posts from 2015

Web App Security Reading - 20150724

I was on a boring conference call this morning and noticed I'd accumulated quite a glut of WebAppSec reading links. I figured I'd dump them here for people to peruse and give me a way to cleanup my bookmarks :) WebAppSec: XSS Vulnerability Shows How Security Issues Can Creep into Popular Software Sector Presentations (2014)   Generic XXE Detection   Hacking HTTPS -> HTTP referrers   Referrer CSRF Bypass ( Not Effective But Alternative )   Playing with Content-Type – XXE on JSON Endpoints   Clickjacking with Jack  Your Application Security Program: Flawless Logic for Big Savings   5 Steps for a Winning AppSec Program  SAML On Breaking SAML: Be Whoever You Want to Be   OWASP : Auth Cheat Sheet : SAML   ZAP SAML Extension (2yrs old as of 201507)  Cookie Bombing Browser Cookie Limits DoS attack on CDN users Cookie Bomb or let's break the Internet The maximum total HTTP header length for BIG-IP WebAccelerator and BIG-IP AAM is now 16,384 bytes Pract

Nexus 7 and Android 5.0.2 - Lag Fix

So I'm not a heavy tablet user, but I did manage to snag a Nexus 7 (8GB) for free at a conference a few years ago. I use it (what I feel is lightly) for a few games, RSA soft token, email, some browsing/reading, etc. After upgrading to 5.0.2 it's been a painful beast. I had initially thought that this was likely due just to NEW OS and OLD hardware. However after doing some digging last night I came across a number of suggestions to wipe the cache partition. Instructions can be found here: How to wipe cache partition Nexus 7 or like this .