New Web Application Security Mailing List 4
An anonymous reader writes "For those slashdotters interested in web application security, WASC (Web Application Security Consortium) has created a new mailing list aply named 'The Web Security Mailing List.' The list is open for discussing important topics such as new attacks types and vulnerabilities, software development, solutions, application firewalls, web servers, database security, tools, etc."
not much discussion. . . (Score:3, Informative)
I also use http://www.sans.org/newsletters/ [sans.org] to keep up to date.
What other resources do people here use to make sure that your server applications are up to date?
Re:not much discussion. . . (Score:1)
This is the first list of this type that I have found. Any suggestions on good discussion boards for php related discussion of security issues?
Any good resources for the generalist? (Score:2)
I'm aware of the overall issues, but really what I haven't found yet is a good, comprehensive guide to securing web applications, particularly Java apps, with both theory and examples. Expertise either comes in the form of experienced consultants or open source frameworks with limited documenation.
I've got Acegi on my list for evalution; however, I like to have a good practical understanding of a p