| SANS Top-20 Internet Security Attack Targets: Web Applications Attacks (2/2) | |||
|
|||
| Web Applications Attacks |
C1.2 How to Determine If You Are at Risk Web scanning tools can help find these vulnerabilities, particularly if they are known bugs. However, to find all potential vulnerabilities requires a source code review. This should be done by the developers prior to release. Inspect your web application framework's configuration and harden appropriately. System administrators should consider scanning web servers periodically with vulnerability scanners, particularly if they run a large diverse range of user supplied scripts, such as a hosting farm. It is impractical for system administrators to perform detailed penetration tests. C1.3 How to Protect against Web Application Vulnerabilities From the PHP system administration and hosting perspective:
From the developer perspective:
C1.4 References OWASP - Open Web Application Security Project http://www.owasp.org OWASP Testing Guide http://www.owasp.org/index.php/OWASP_Testing_Guide_v2_Table_of_Contents OWASP Guide - a compendium of secure coding http://www.owasp.org/index.php/Category:OWASP_Guide_Project OWASP Top 10 - Top 10 web application security weaknesses http://www.owasp.org/index.php/Category:OWASP_Top_Ten_Project Suhosin, a Hardened PHP project to control the execution environment of PHP applications http://www.hardened-php.net/suhosin/ PHP Security Features http://php.net/features.safe-mode |
| Page: 1 2 |
| Return to Category | Return To Main Index |
| Identity Theft Protection Services : | |
|
LifeLock Identity Theft Prevention Solution
Veracity Credit Optimization Services Equifax Credit Watch |
Free Credit Report Identity Truth Privacy Matters 123 |














