Understanding Web application security challenges This paper explains what you can do to help protect your organization, and it discusses an approach for improving your organization's Web application security.
IBM Rational AppScan: Cross-site scripting explained This article walks you through the steps and code work needed to design and implement a weather forecast application by using AJAX with a Relational Record List, combo box, Panels-Tabbed, and Data Tree components in IBM Rational Application Developer.
Web application security: automated scanning versus manual penetration testing There are two primary methods for discovering Web application vulnerabilities: using manual penetration testing and code review or using automated scanning tools and static analysis. The purpose of this paper is to compare these two methods.