User Enumeration

One of the most common and underestimated web application vulnerabilities I find frequently is user enumeration. Simply put, I can figure out a list of valid user accounts that are allowed to login to an application. This isn’t just assuming there’s a common user...

ThreatView – August 2012 QSA vs ISA

Many organizations that must comply with the Payment Card Industry Data Security Standard (PCI DSS) are asking what the differences are between QSA’s and ISA’s and which direction they should take with their program.  We address this question in the latest...