XSS, CSRF, Injections and other forms of common web application exploitations are disclosed and discussed in order to further programmers' understanding of these easily preventable security issues.
I follow the responsible Full Disclosure Policy giving site maintainers sufficient time to secure exploits. Also see my site, vancouver wedding photography.
A flaw in Rails’ handling of Unicode leads to a hole in some of the framework’s major applications. Twitter handled it gracefully as did Rails… 37Signals, not so much.