2007
Home | Email Standards Project
by mbertier & 22 others (via)The Email Standards Project works with email client developers and the design community to improve web standards support and accessibility in email.
PHPIDS » Web Application Security 2.0 » Index
by mbertier & 1 other (via)PHPIDS (PHP-Intrusion Detection System) is a simple to use, well structured, fast and state-of-the-art security layer for your PHP based web application. The IDS neither strips, sanitizes nor filters any malicious input, it simply recognizes when an attacker tries to break your site and reacts in exactly the way you want it to. Based on a set of approved and heavily tested filter rules any attack is given a numerical impact rating which makes it easy to decide what kind of action should follow the hacking attempt. This could range from simple logging to sending out an emergency mail to the development team, displaying a warning message for the attacker or even ending the user’s session.
Exceptional Performance
by mbertier & 3 othersYahoo!'s Exceptional Performance team evangelizes best practices for improving web performance. They conduct research, build tools, write articles and blogs, and speak at conferences. Their best practices center around the rules for high performance web sites.
[ANN] mod_concat
by mbertier (via)The ability to concatenate CSS or javascript files into a single HTTP request.
0x000000 ◊ The Hacker Webzine
by mbertierI've talked about CSRF before, but this time I wanted to show some of the underlying basics of it and explain why it isn't a new trick or something special. It is part of browsers and the way HTTP works, also to remove any argument that POST should be safer then GET. I know this is Internet basics, it still can be refreshing to read it over from time to time.
XSS (Cross Site Scripting) Cheat Sheet
by mbertier & 17 others (via)This page is for people who already understand the basics of XSS attacks but want a deep understanding of the nuances regarding filter evasion.
Dangers of CSRF and XSS / Articles / Community
by mbertier & 1 other (via)In this article, we will show you how CSRF and XSS work and how to defend against them. To dispel the myths about these attacks, I will assume the role of a hacker and show how the supposedly harmless injection of tiny bits of HTML can perform amazing things, from stealing the user's identity to a completely transparent rewrite of site content.
2006
BindShell.Net: BeEF
by mbertierBeEF is the browser exploitation framework. Its purposes in life is to provide an easily integratable framework to demonstrate the impact of browser and cross-site scripting (XSS) issues in real-time.
Optimizing Page Load Time - die.net
by mbertier & 7 others (via)While working on optimizing page load times for a high-profile AJAX application, I had a chance to investigate how much I could reduce latency due to external objects. Specifically, I looked into how the HTTP client implementation in common browsers and characteristics of common Internet connections affect page load time for pages with many small objects.
The ALA Primer: A Guide for New Readers
by mbertier & 3 othersA List Apart offers hundreds of articles on design, markup, style, accessibility, usability, and more. We’ve selected a few that you might want to start with.
CSS support in HTML emails of Hotmail, Yahoo! Mail and Gmail
by mbertier & 10 othersI tested the vast majority of CSS properties and some CSS practices to see how each web based client would react. You will find the results below.
Zend Developer Zone | PHP Best Practices: Creating a Blueprint for PHP Applications
by mbertierWhat is the one true path to creating a successful PHP application? Does it exist? Does everyone know what it is? What dangers should I avoid? What works, what doesn’t? Is there a guide that will lead me down this path?
Yahoo! Developer Network Home - Welcome!
by mbertier & 12 othersWelcome to the Yahoo! Developer Network. We help software developers integrate their Web sites and applications with Yahoo! using standard technologies such as XML and RSS.
Yahoo! Developer Network: Graded Browser Support
by mbertier & 2 othersGraded Browser Support offers two fundamental ideas:
* A broader and more reasonable definition of “support.”
* The notion of “grades” of support.
Joshua Schachter, del.icio.us - Notes
by mbertier & 5 othersThings to look out for when building a large application.
2005
WebPatterns
by mbertier & 2 othersWebPatterns is a place to discuss, document and collaborate on patterns for web design and development.
IEs 4 Linux - Sergio Lopes
by mbertier & 10 others (via)IEs for Linux is a simple Bash Script program that installs Internet Explorer 6, 5.5 and 5 on Linux using Wine. The whole process is automatic and very easy.
Particletree · 4 Layers of Separation
by mbertier & 7 others (via)I believe, however, that a fourth layer of separation is being neglected: the data layer. This layer is represented by server side scripts that process and retrieve information from a data source.
Sitemap Protocol
by mbertier & 6 others (via)Décrit un protocole pour guider les moteurs de recherche dans les pages d'un site Web (en anglais).
Dive Into Greasemonkey
by mbertier & 40 others (via)Dive Into Greasemonkey is a book about programming with Greasemonkey, a Firefox extension for customizing web pages.
Une mine d'or : Les présentations du IA Summit 2005
by mbertier (via)# Information Architecture for Content Management,
# Select Country: The Art of the Global Gateway,
# STUX - Integrating IA deliverables in a web application development methodology.
Cacheability Engine
by mbertier & 3 othersTo help you understand how Web Caches will treat a Web page, the Cacheability Engine will look at a URL (and optionally any images or objects associated with it), giving both specific cache-related data about it, and a general commentary on how cacheable the object is.
1
(25 marks)