Palisade Magazine

 
HTTP Request Smuggling

September 2006

HTTP Request Smuggling

by Prashant Gawade

With the advent of HTTP-aware firewalls, IPSs, a lot of developers relax a little bit on strengthening the security of an application. Application firewalls are able to lock out most of the automated attacks on websites. However a new attack vector has been discovered which can bypass application firewalls too. HTTP request smuggling allows an attacker to send malicious requests across proxies and firewalls to the web server. Let’s have a short description of the attack techinique.… more →

Anti-Phishing Techniques - Detection Measures

by Jose Varghese, CISSP, GSEC, GCIH, CBCP, BS7799 LA

As was outlined in the first part of this series, there are several methods to protect users from phishing attacks. But prevention is not enough. We need detection measures to get early warning signals when a phishing attack is being planned or is in progress.Before we get into detection measures let us look at the steps the attackers does while executing a phishing attack.… more →

Securing IIS Web Servers

by Siddharth Anbalahan

In our previous article we showed how to securely deploy one of the most popular web servers, i.e. Apache web server. In this article we cover how we can secure the IIS 6.0 web server. Microsoft’s initiative towards security, Trustworthy Computing, is based on four pillars as defined by Microsoft:… more →

QuizQuiz: Choose the most effective password

Which of the following is the most effective password?

  1. XH#4@r4$8
  2. Kate1980
  3. Asterixh@sgoneHome

more →

Search this website

 Search website

Stay Informed

Want to know when the new issues are out? Just fill in your details, we will take care of notifying you when new issues are released:




Subscribe  Unsubscribe

Write to Us

All flowers, brickbats and suggestions are welcome. You can put in yours on the feedback page.

News & Events

  • 21.05.09. ICICI Bank and Paladion Have Been Awarded the Best Banking Security Systems Project by the Asian Banker IT Implementation Awards Program
  • 20.04.09. Info Security Products Guide Names Plynt Certification Program Winner of the 2009 Tomorrow’s Technology Today Award
  • 15.02.09. Paladion/Plynt Launches a PCI Solution Package for the Retail Industry to Meet Demands for Enterprise Merchants Seeking PCI DSS Compliance
  • 10.06.08. Paladion is presenting on “Safeguarding SaaS” at the SaaS University in Boston, June 18-19
  • 17.03.08. Asian Banker awards Kotak Mahindra and Paladion the best security implementation project for 2007