Connect With WRD
feed via e-mail
feed via e-mail

Archive for the ‘Security’ Category

Cryptico.js is an easy-to-use JavaScript library for encrypting text on the client-side.

It has support for RSA + AES methods and the text can be encrypted with any given bit length (228, 1024, etc.).

Cryptico.js

The content is encrypted with a public key and it can only be decrypted with that key (which makes sense if the recipient already has that information).

Cryptico.js doesn't require any JS frameworks to function and it is well-documented.

Captchas are usually hard to use and boring. However they help a lot in minimizing headaches on the application-side by making sure that "an action is performed by a human".

MotionCAPTCHA, a jQuery plugin, offers a different type of captcha by asking the users to draw the shape displayed. It is not only different but also fun and can even be easier to-use for touch devices.

The project is currently a proof-of-concept considering the captcha is only verified on the client-side and can be manipulated. However, the next version is planned to have server-side and better browser support. Looking forward to it!

MotionCAPTCHA

NuCaptcha is a free captcha service that uses motion video to authenticate human web interactions.

Compared to image-based captchas, it is a harder-to-recognize solution for bots and can be read easier by humans which is great.

NuCaptcha

With the help of an API, NuCaptcha can be implemented into any website (sample codes provided) and there is also a WordPress plugin offered.

The captchas can be customized in means of skin, background and message displayed which helps a better visual integration with the websites.

Websites are getting more and more complex everyday and there are almost no static websites being built.

Security GuyToday, the simplest website has at least a contact or newsletter form and many are built with CMS systems or it may be using 3rd party plugins, services, etc. that we don't have an exact control over.

Even if the website is 100% hand-coded, we trust what we created and think that it is safe, it is still possible that a special character is not sanitized or we are not aware of a new attacking technique.

So, it is really hard to say "my website is safe" without running tests over it. The good part is there are powerful and free web application security testing tools which can help you to identify any possible holes.

Before presenting them, let's remind the classic: "something can be secure as only as its weakest link" (which also tells us that it is not always the application and can still be the server it is hosted or that easy to remember FTP password).

Netsparker Community Edition (Windows)

Netsparker Community Edition

This is the free-community edition of the powerful Netsparker which still comes with a bunch of features and also false-positive-free.

The application can detect SQL Injection + cross-site scripting issues.

Once a scan is complete, it displays the solutions besides the issues and enables you to see the browser view and HTTP request/response.

Websecurify (Windows, Linux, Mac OS X)

Websecurify

Websecurify is a very easy-to-use and open source tool which automatically identifies web application vulnerabilities by using advanced discovery and fuzzing technologies.

It can create simple reports (that can be exported into multiple formats) once ran.

The tool is also multilingual and extensible with the add-on support.

Read the rest of this entry »

PHPSecInfo is a PHP environment security auditing tool which can be useful as part of a multilayered security approach.

The script runs a series of tests to identify potential security issues and offer suggestions.

PhpSecInfo

It can be reached easily by calling the "index.php" files after uploading the project folder.

PHP Security Consortium also has a PHP security guide which you may want to check out.

P.S. PhpSecInfo is definitely not a replacement for secure coding practices & doesn’t audit PHP code.

  • Tags:
  • Filed under: Extras, Other License, Security
  • 1 Comment
  • VidoopCAPTCHA is a free verification solution that works image-based which is unusual compared to the widely-used text-based ones.

    It aims to be a more user-friendly solution as text-based captchas can sometimes be so hard to read for humans besides bots.

    Image Based Captcha

    VidoopCaptcha is a hosted service & have plugins for WordPress, Ruby on Rails, and Drupal. Also, there are libraries for programming languages such as PHP, Python, and .NET.

    It offers some customization options like category, number of grid squares, color & grid size. For a demo of this security resource, click here.

    Normally, when a data is submitted, it is sent in plain text if no SSL is used.

    jCryption is a jQuery plugin for encrypting POST/GET data submitted by forms.

    It uses public-key algorithm of RSA for the encryption & has a PHP file for handling the decryption of data.

    JavaScript Encyrption

    Some features of jCryption:

    • encryption up to 2048 bit
    • AjaxSubmit supported
    • doesn’t block the browser on calculations

    The plugin is easy to install, use and extend. Calling the jCryption function:

    $("#formID").jCryption();

    and handling the data with the ready-to-use PHP function is enough.

    DesignShack is presenting a very nice tutorial on creating a virtual keyboard with jQuery (script can be downloaded).

    Such virtual keyboards are generally used in bank websites or forms that require extra security. They are a step for preventing keyloggers (but may not be an absolute solution as keyloggers are getting smarter).

    jQuery Virtual Keyboard

    It is very easy to add new characters to the keyboard if needed & the keyboard can be dragged to anywhere on the screen.

    To check the demo, click here.

    Internet Captcha is a Flash-based captcha script which can be generated online with a configuration interface.

    It lets you define all the variables of the captcha including the distortion level, color, Flash effect & more.

    Flash Captcha

    The configuration wizard created the necessary JavaScript and ASP / PHP files and shows how to install this captcha script step by step.

    One nice feature of Internet Captcha is, it shows you the security level of the captcha you designed.

    Scrawlr is a free software for scanning SQL injection vulnerabilities on your web applications.

    It is developed by HP Web Security Research Group in coordination with Microsoft Security Response Center.

    Free SQL Injection Scanner

    Scrawlr crawls a website while simultaneously analyzing the parameters of each individual web page for SQL Injection vulnerabilities.

    After the scanning process, if it can find, it even shows your database table names as a proof of the possible SQL injection vulnerabilities.

  • Tags:
  • Filed under: Extras, Other License, Security
  • 8 Comments
  • Uptime Robot
    feed-holder
    FeedBurner
    • aXmag - Flash Page Flip Magazine Software, PDF to Flash Converter
    • PSD to HTML
    • ManageWP
      PSD to HTML