Cassette – Asset management for .NET web apps

A few weeks ago i’ve started using Cassette, a very nice asset management tool for .net web applications. It will basically take your assets ( javascript, coffescript, css, images ) and do the right thing with them ( combine, minify etc).

While working with it i had a few issues which I’ve  managed to solve and i would like to share them.… read full article

ASP.NET MVC or ASP.NET just got plesent

I’ve been really busy the last months with the new job where we use c#. I’ve grown found to it … it has a lot of nice features … lambda expressions, anonymous types, generic types. Sure there are a lot of thing that can be improved like real generic types ( aka C++ templates ) but it’s a really reliable tool.

In the past I’ve worked on a few… read full article

WordPress Exploit Scanner Plugin

I’ve found a few days ago this plugin and i would like to share with everybody since it may help secure the web. This plugin scans the wordpress installation folder for paterns usualy found in exploits/throjans/malware web scripts. The plugin produces quite a few false positive alerts but also it’s very easy to spot suspicious code in suspicious files.

It would be nice if… read full article

Flash on FreeBSD – Gnash

Watching flash content on FreeBSD was and still is a problem. It\’s sad Adobe won\’t publish a native version of flash for FreeBSD, or even better open the sources for the flash player. It\’s strange they don\’t, unless the sources are a real mess I don\’t see any strong reason for not doing so. Now that rumors are found about new technologies for web graphics likesvg, html 5, flash might not be so popular in the future. read full article

Wt, C++ Web Toolkit

Wt (pronounced \’witty\’) is a C++ library and application server for developing and deploying web applications. It is not a \’framework\’, which enforces a way of programming, but a library. read full article

Web application security flows

Here goes… my first security related post :)

Intro

First i must say that this will not be a way to prove that your application is secure, it will only be a quick & dirty way of finding common bugs in web applications. The following will be a few techniques that i tend to use the first time i see an web application ( and generally a database application ). I will use PHP for the few code examples but the vulnerabilities presented are not limited to PHP, in fact are independent of the server-side programming language used.… read full article