SuperGeekery: A blog probably of interest only to nerds by John F Morton.

A blog prob­a­bly of inter­est only to nerds by John F Mor­ton.

Link List

Wel­come to my link library. These are not links to con­tent I have cre­at­ed unless you see that men­tioned in the link’s descrip­tion. These are links I found inter­est­ing enough to want to keep track of. If you read Craft Link List, the Craft CMS newslet­ter I used to write, this page is a replace­ment of sorts for that exer­cise. Enough talk. Let’s hit the links.

Tagged with ”security”

Reset tag search
10Nov2024

HTTP Security Headers: A complete guide to HTTP headers

HTTP Secu­ri­ty Head­ers are essen­tial to any web­site. Learn about the HSTS head­er, Con­tent Secu­ri­ty Pol­i­cy head­er CSP, XSS pro­tec­tion, cache con­trol, strict trans­port secu­ri­ty, set-cook­ie head­er, and many more http head­ers in this com­pre­hen­sive guide with exam­ples and take your web­site secu­ri­ty head­er game to the next lev­el with Dark­re­lay.

30Oct2024

HTML Form Validation is heavily underused

HTML Forms have pow­er­ful val­i­da­tion mech­a­nisms, but they are heav­i­ly under­used. In fact, not many peo­ple even know much about them. Is this because of some flaw in their design? Let’s explore.

20Dec2023

Terrapin Attack

The Ter­rapin attack is a pre­fix trun­ca­tion attack tar­get­ing the SSH pro­to­col, where the integri­ty of SSH’s secure chan­nel is com­pro­mised by manip­u­lat­ing sequence num­bers dur­ing the hand­shake, allow­ing an attack­er to remove mes­sages from the secure chan­nel with­out detec­tion.

28Nov2023

OWASP Top Ten | OWASP Foundation

The OWASP Top 10 is the ref­er­ence stan­dard for the most crit­i­cal web appli­ca­tion secu­ri­ty risks. Adopt­ing the OWASP Top 10 is per­haps the most effec­tive first step towards chang­ing your soft­ware devel­op­ment cul­ture focused on pro­duc­ing secure code.