Updated: 4/30/2007; 4:06:25 PM.
Mark O'Neill's Radio Weblog
        

Monday, October 24, 2005

"Rather than thinking of how to implement security in each part of the web services Morris suggested implementing security as web services themselves. He advocated security in depth by using existing features like directories and web access authorization and the like (which makes sense, no reason to re-invent the wheel time and time again). XML introduces a lot of new security threats like SQL injection through XML payload, XPath Injection, unexpected attachments (and how to deal with those), malformed XML etc."

More at: http://balrog.de/security/archives/2005/10/18/141_rsa-conference-security-of-web-services-vic-morris

 

 


2:34:55 PM    comment []

© Copyright 2007 Mark O'Neill.
 
October 2005
Sun Mon Tue Wed Thu Fri Sat
            1
2 3 4 5 6 7 8
9 10 11 12 13 14 15
16 17 18 19 20 21 22
23 24 25 26 27 28 29
30 31          
Sep   Nov