If at first you don't succeed, call it version 1.0

Contact Me

Sarvesh Kushwaha
Email : sarveshkushwaha@outlook.com

Total Pageviews

Powered by Blogger.

Showing posts with label Asp.net Security. Show all posts
Showing posts with label Asp.net Security. Show all posts

Saturday, 3 January 2015

Hack proof your asp.net applications from Session Hijacking


Introduction:

This article is the Part-6 of my series Hack Proof your asp.net and asp.net mvc applications. In this article, I will describe what exactly Session Hijacking (Man-in the-middle-attack) is and how a hacker exploits it and how we can prevent Session Hijacking attack in asp.net applications.

Background:

Wednesday, 15 October 2014

Hack proof your Javascript using javascript Obfuscation in ASP.NET applications


Introduction:

This article is the Part-5 Article of my series Hack Proof your asp.net and asp.net mvc applications.
In this article i will describe how to obfuscate your JavaScript code (Your written business logic in JavaScript or those  JavaScript libraries you don't want to expose to others) in asp.net application with visual studio.

Background :

You can read previous article of this series from below links :

    1. Secure your ASP.NET applications from SQL Injection
    2. Secure your ASP.NET applications from XSS Attack
    3. Secure your ASP.NET applications from CSRF Attack
    4. Secure your ASP.NET applications from Sensitive Data Exposure and Information Leakage

    Friday, 6 June 2014

    Hack proof your ASP.NET applications from Sensitive Data Exposure and Information Leakage


    Introduction:

    This is Part 4 of my series Hack proof your asp.net application.In this article ,I will describe How we sometimes unintentionally expose some sensitive information or leak some information to a hacker , who used that information to hack us. Keeping These terms separate "Sensitive Data exposure" which can directly harm to an individual or an organization, "Information leakage" are which helps attacker to perform malicious activities.Both terms are correlated and we can say Information leakage can contain Sensitive data exposure and vice versa.

    Background:

    You can read previous article of this series from below links :

    Sunday, 13 April 2014

    What is Heartbleed bug and Its solutions ?


    Introduction 
    From last few days Heartbleed trending on the internet and saying to the internet, I am the evil. People are calling this bug as "Biggest Security Threat" to the internet. Some Websites called this bug "Catastrophic".
    I was Gawked to know i was not safe since 2011 December Since OpneSSL included Heartbeat Extension.







    Sunday, 24 November 2013

    Hack Proof Your Asp.Net Application Part 3 (Cross Site Request Forgery)


    Introduction:

    This is part -3 of my series Secure your Asp.Net Applications. In this article, I will describe what exactly Cross Site Request Forgery (CSRF) is and how hacker exploit it and how we can prevent from CSRF attack.

    Background:

    You can read my previous article of this series from :
    cross site request forgery is also known as one click attack, sea surf and session riding and abbreviated as CSRF. CSRF attack is kind of secuirty exploit attack in which attacker uses the authentication of the victim on victim's browser.

    Saturday, 6 July 2013

    Hack Proof Your Asp.Net Application Part 2 (Cross Site Scripting-XSS)


    Introduction -

    This is part -2 of my series Secure your Asp.Net Applications. In this article, I will describe what exactly Cross site scripting (XSS) is and how hacker exploit it and how we can prevent from XSS attack.
    Background:
    For part-1 of this series you can check from HERE  which is Secure your asp.net application from SQL Injection.

    Cross-Site Scripting -
    Cross-Site Scripting is kind of security exploit in which attacker inserts malicious code of his choice(Mostly script) into web page or in database, without user's knowledge .XSS in itself is a threat which is brought by the internet security weaknesses of client-side scripting languages, with HTML and JavaScript (others being VBScript, ActiveX, HTML, or Flash) as the prime culprits for this exploit.

    Thursday, 6 June 2013

    Hack Proof Your Asp.Net Applications- PART-1 (SQL Injection)


    Ahhhh a developer never wants to get hacked his own web application .but intruder , malicious persons are more than developers , and i used to be one of them and then turned into a developer .as i have walk in both the shoes , so i have decided to write a series of articles which will definitely help to hack proofing a web application .
    A developer should always concerned about hack attempts in their applications ,and its a developer duty as well .lots of online tools , spoofing tools , sniffers tool  etc are available on the internet .so even a normal internet user can turned into a hacker . i hope everybody  knows the consequences of being hacked , so by not describing them , i better do write my article.
    lets gets start understanding of some hacks and how a developer can prevent them .in this first article i will start by sql injections.