๐Ÿฆž๐ŸŒฏ Lobster Roll

Thread

A Magical Web Screenshot Project (github.com)
Crystal Ball is a library that takes an array or file of URLs and returns a report with screenshots (using Puppeteer), application headers and src/href references.

Stories related to "A Magical Web Screenshot Project" across the full archive.

A Magical Web Screenshot Project (github.com)
Crystal Ball is a library that takes an array or file of URLs and returns a report with screenshots (using Puppeteer), application headers and src/href references.
New Rule: Every website must disclose their password storage format on the signup page. (gizmodo.com)
Scared to disclose? It's too weak.
Content hosting for the modern web (googleonlinesecurity.blogspot.com)
Web Cryptography API (w3.org)
Mailvelope - client-side PGP encryption for webmail (mailvelope.com)
Critical crypto bug in OpenSSL opens two-thirds of the Web to eavesdropping (arstechnica.com)
Webservers shouldn't have direct access to your private keys. (plus.google.com)
Best practices in modern web projects - Random notes by Arvid Andersson (blog.arvidandersson.se)
The Ur/Web Manual (enn.github.io)
Ur/Web is a language and framework for building websites using strong types to ensure certain kinds of correctness (like well formed output, no dead links, no xss or sql injection). Here is the Ur/Web manual converted to HTML. This is the main site for the language and compiler: http://www.impred...
Free alternatives to 000webhost (blog.toppagedesign.com)
New Class of Vulnerability in Perl Web Applications (blog.gerv.net)
Jailed 0.2 now runs untrusted code inside a web-worker inside a sandboxed iframe (github.com)
phpBB website compromised (phpbb.com)
Signing in to websites with SSH (vtllf.org)
Critical vulnerabilities in JSON Web Token libraries (timmclean.net)
Big Mess o' Wires ยป Web Site Hacked (bigmessowires.com)
I am not the owner, but I'm definitely curious as to how the breach may have happened. There's not a huge amount of information but I'm sure people might be able to make suggestions as to how this might have happened.
It's time for the distributed, permanent web (ipfs.io)
Cross-Site WebSocket Hijacking (CSWSH) (christian-schneider.net)
The Web Authentication Arms Race โ€“ A Tale of Two Security Experts (blog.slaks.net)
Web login using SSH (github.com)
Advice on my prototype web template language designed for security? (github.com)
I know all the advice on the internets says that you shouldn't develop yet another web templating language, but I haven't found anything that matches my requirements as the author of an (open source) scriptable web app which provides plugins with a web app framework. I have a particular thing abo...
Angler Exploit Kit Continues to Evade Detection: Over 90,000 Websites Compromised (researchcenter.paloaltonetworks.com)
Let's Encrypt & Nginx: State of the art secure web deployment (letsecure.me)
The Basics of Web Application Security (martinfowler.com)
KeyBox: Web-Based SSH Access and Key Management (github.com)
How to set up Free SSL for your Website (jeremymorgan.com)
How to get truly free SSL for your website with letsencrypt
New debugging method found 23 undetected security flaws in 50 popular Web apps (news.mit.edu)
How to Install Free SSL for Your Website (dzone.com)
CertBot: Automatically enable HTTPS on your website with Let's Encrypt certs (certbot.eff.org)
Its written using Python - [Github](https://github.com/certbot/certbot)
JWT Inspector - Chrome extension to inspect and debug JSON Web Tokens (jwtinspector.io)