Security implications of adding all domains to CORS (Access-Control-Allow-Origin: *)

Cross-Site Request Forgery attacks are far and away the primary concern that Access-Control-Allow-Origin addresses. Ryan is certainly correct regarding content retrieval. However, on the subject of making the request there is more to say here. Many web sites now provide RESTful web services that expose a wide range of features that may involve making significant … Read more

How to enable DDoS protection?

DDOS is a family of attacks which overwhelm key systems in the datacenter including: The hosting center’s network connection to the internet The hosting center’s internal network and routers Your firewall and load balancers Your web servers, application servers and database. Before you start on building your DDOS defence, consider what the worst-case value-at-risk is. … Read more

Hata!: SQLSTATE[HY000] [1045] Access denied for user 'divattrend_liink'@'localhost' (using password: YES)