top of page
Search

Jeremy Druin
Apr 2, 20211 min read
How to Check HTTP Headers
HTTP response headers can impact the user experience and the security of the web or mobile application. Server administrators can...
66 views0 comments

Jeremy Druin
Mar 22, 20211 min read
Retiring Obsolete JavaScript Libraries
One of the most over-looked issues in web applications is vulnerabilities in someone else's code; 3rd-party JavaScript libraries. Vendors...
74 views0 comments

Jeremy Druin
Mar 6, 20211 min read
What is Content Security Policy?
Content Security Policy (CSP) is a security framework built into the browser. CSP allows the browser to block content from sources other...
46 views0 comments


Jeremy Druin
Mar 1, 20211 min read
Yum! Secure Cookies
Cookie security is an oxymoron. Cookies exist in the browser; an inherently insecure location. However, there are several best-practices...
26 views0 comments

Jeremy Druin
Feb 25, 20211 min read
How HTTP Headers impact Application Security (by Example)
Web server configuration can impact the security of the web site and underlying application. These headers can be confusing so it is not...
33 views0 comments

Jeremy Druin
Feb 24, 20211 min read
What is DevSecOps?
DevSecOps is a development methodolgy that enables rugged software with quality baked in from the start. A key component is security....
31 views0 comments

Jeremy Druin
Feb 22, 20211 min read
ZAPping Web Application Vulnerabilities
Vulnerability assessment is a great addition to development lifecycles. Vulnerabilities found early are easier and cheaper to fix plus...
19 views0 comments

Jeremy Druin
Feb 22, 20211 min read
Weak HTTPS Ciphers? There is an app for that
HTTPS connection depend on the underlying cryptopgraphic algorithms that are available to the web server. Also, the web server...
14 views0 comments

Jeremy Druin
Feb 21, 20211 min read
How Output Encoding Stops Cross-site Script (XSS) Attacks
Output encoding is a powerful defense against cross-site script (XSS) attacks. Output encoding clearly marks information in web pages as...
20 views0 comments
bottom of page