smartsecurity.blogspot.com
Smart Security by Dharmesh M Mehta: October 2009
http://smartsecurity.blogspot.com/2009_10_01_archive.html
Smart Security by Dharmesh M Mehta. An Application Security Blog. Thursday, October 08, 2009. Application security should be addressed in initial SDLC stages. IT applications are akin to the organization's blood vessels because they carry critical information and execute key processes. However, due to a peripheral approach to security, application security is often neglected. If you estimate risk correctly from the beginning, it will also help you to save on costs. According to an industry statistic,...
smartsecurity.blogspot.com
Smart Security by Dharmesh M Mehta: Getting Hands Dirty with Ettercap Tool
http://smartsecurity.blogspot.com/2010/06/getting-hands-dirty-with-ettercap-tool.html
Smart Security by Dharmesh M Mehta. An Application Security Blog. Monday, June 28, 2010. Getting Hands Dirty with Ettercap Tool. Ettercap is a suite for man in the middle attacks on LAN. It features sniffing of live connections, content filtering on the fly and many other interesting tricks. It supports active and passive dissection of many protocols (even ciphered ones) and includes many feature for network and host analysis. Subscribe to: Post Comments (Atom). View my complete profile. ACE Team at Micr...
smartsecurity.blogspot.com
Smart Security by Dharmesh M Mehta: March 2010
http://smartsecurity.blogspot.com/2010_03_01_archive.html
Smart Security by Dharmesh M Mehta. An Application Security Blog. Wednesday, March 10, 2010. About the 'Rugged' Initiative. As most of the readers on my blog would be knowing, the Security experts in February launched a new effort to ensure software is written from the ground up with security in mind - a philosophy and message they're aiming at people outside of the security industry. The Indian IT industry spends so much on training costs, as more than 70% of fresh graduates are not employable/productiv...
smartsecurity.blogspot.com
Smart Security by Dharmesh M Mehta: March 2011
http://smartsecurity.blogspot.com/2011_03_01_archive.html
Smart Security by Dharmesh M Mehta. An Application Security Blog. Thursday, March 17, 2011. IRCTC - India's Rail Ticket Booking Website which is sought to be a secure platform for the citizens booking their tickets has few simple security configurations missing. An example is the auto-complete not set to off on their payments page - a practice which most of the secure web applications follow for sensitive pages right from login page. Below is a snapshot. Links to this post. Tuesday, March 15, 2011. How T...
smartsecurity.blogspot.com
Smart Security by Dharmesh M Mehta: August 2009
http://smartsecurity.blogspot.com/2009_08_01_archive.html
Smart Security by Dharmesh M Mehta. An Application Security Blog. Friday, August 28, 2009. No Built-In Response.HTMLEncode in Java. Why doesn't Java have a built-in HTMLEncode function? With security vulnerabilities like Cross-Site Scripting (XSS) luring around since so many years, I am wondering why hasn't Java yet come up with its own function for Encoding chars which are malicious. I believe 'Sun' . sorry.'Oracle' should think of having this simple thing built-in. Links to this post.
smartsecurity.blogspot.com
Smart Security by Dharmesh M Mehta: Simple Autocomplete
http://smartsecurity.blogspot.com/2011/03/simple-autocomplete.html
Smart Security by Dharmesh M Mehta. An Application Security Blog. Thursday, March 17, 2011. IRCTC - India's Rail Ticket Booking Website which is sought to be a secure platform for the citizens booking their tickets has few simple security configurations missing. An example is the auto-complete not set to off on their payments page - a practice which most of the secure web applications follow for sensitive pages right from login page. Below is a snapshot. March 24, 2011 1:48 PM. View my complete profile.
yashkadakia.com
Indian Information Security Incidents Gallery ~ Yash Kadakia
http://www.yashkadakia.com/2009/02/indian-security-incidents.html
Security, Startups, Code and Coffee. Security Brigade InfoSec Pvt. Ltd. Security Audit Free Demo. Wednesday, February 25, 2009. Indian Information Security Incidents Gallery. Posted on 11:55 PM by Yash Kadakia. I was recently on the phone with Dinesh O'Bareja. And he mentioned a blog he started sometime back to document Indian Information Security Incidents. I think its a great initiative on his part and one that we definitely require in the Indian IT Security space. So if anyone out there has witnessed ...
smartsecurity.blogspot.com
Smart Security by Dharmesh M Mehta: December 2009
http://smartsecurity.blogspot.com/2009_12_01_archive.html
Smart Security by Dharmesh M Mehta. An Application Security Blog. Sunday, December 20, 2009. Latest Phishing Site of ICICI Bank. I just came across a phish email created for ICICI Bank Users. Sharing the screen-shots for fun. Have reported the fake site to antiphishing.org. Phishing Site Link: http:/ adamthompson.org/infinity.update/BANKAWAY.sessionid/update;RetUser/Y&AppSignOn.icicibank.co.in/index.html. Links to this post. Subscribe to: Posts (Atom). View my complete profile. Threat Analysis - NASSCOM.
smartsecurity.blogspot.com
Smart Security by Dharmesh M Mehta: Past few months
http://smartsecurity.blogspot.com/2011/03/past-few-months.html
Smart Security by Dharmesh M Mehta. An Application Security Blog. Tuesday, March 15, 2011. For the past few months or rather lemme say a year, I haven't been actively writing out here. I have been spending my time on other security aspects of my life. I secured myself from being a bachelor (got married :D), secured my Post Graduation (completed my Executive Management from IITB) and secured my job too. :). July 08, 2011 5:52 AM. Congrats and party :). Subscribe to: Post Comments (Atom).
SOCIAL ENGAGEMENT