This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org

Template:Application Security News

From OWASP
Revision as of 09:12, 11 July 2006 by OWASP (talk | contribs)

Jump to: navigation, search


Jul 11 - Yankee predicts AAP to replace WAF
In a report titled, "Application Assurance Platforms Arise from Web App Firewall Market’s Ashes," Yankee projects overall product revenue in the evolving AAP market to grow to $230 million by 2009. AAP's are predicted to combine the web application firewall, database security, XML security gateway and application traffic management segments.
Jul 7 - Who's changed their process?
"All software has security defects," insists Michael Howard, senior security program manager at Microsoft. "You either do something about it, or you don't...What worries me is how little attention [software] vendors are paying to this. I know of nobody else who has changed their process."
Jul 7 - PCI update will mandate application security
"Visa U.S.A. Inc. and MasterCard International Inc. will release new security rules in the next 30 to 60 days for all organizations that handle credit card data, a Visa official said this week. The rules will be the first major updates to the one-year-old Payment Card Industry (PCI) data security standard, which analysts said is slowly but surely being adopted. Extensions are aimed at protecting credit card data from emerging Web application security threats."
Jul 5 - Even Google has application security issues
RSnake writes about XSS, CSRF, and open redirect problems in google.com. "While surfing around the personalization section of Google I ran accross the RSS feed addition tool which is vulnerable to XSS. The employees at Google were aware of XSS as they protected against it as an error condition, however..."
Older news...