Lots of App Sec news

I leave for a few days, come back and the security community has gone crazy with lots of exciting news. Here are a few things worth checking out:
 

  • Apparently Mike Bailey and the guys over at skeptikal cracked StrongWebMail's challenge. Should be interesting to see where that goes. Link Here
  • Just another reason why OS Command issues in web apps are bad, even if the web server is a virtual Guest. Link Here
  • For some reason, there are a number of iPhone/Mobile articles out there that sound scary. Guess what, it is scary!! It will happen, its just a matter of time. Links Here and Here
  • Score number two for the good guys vs. rouge ISPs. The latest is a move by the FTC to shut down Triple Fiber Network for serving too much bad stuff. Link Here
  • Who says crime doesn't pay? Jeff Moss is now on the DHS Cyber Security council. =) Link Here