Web Application Security

Descrição

Web Application Security Notas sobre Web Application Security, criado por Namita Tomar em 13-11-2018.
Namita Tomar
Notas por Namita Tomar, atualizado more than 1 year ago
Namita Tomar
Criado por Namita Tomar mais de 5 anos atrás
5
0

Resumo de Recurso

Página 1

Injection :   What ? Untrusted user input is interpreted by server and executed What is impact ? Data modified and stolen. How to prevent it ? - Reject invalid/untrusted input - Use latest frameworks - Hire penetration testers

Página 2

Broken Authentication and session management   What it is ? Incorrectly build auth and session management which allow attackers to impersonate other users. Impact ? Attacker can take identity of victim. How to prevent? Don't develop your own authentication scheme

Página 3

Cross Site Scripting (XSS)   What it is ? Untrusted user input is interpreted by Browser and executed. What is the impact ? Hijack user sessions, deface websites and change content How to prevent it ? Escape untrusted data use latest UI framework.

Página 4

Broken Access Control   What it is ? Restrictions on what authenticated users are allowed to do are not properly enforced.  Impact ? Attackers can access data, view sensitive files and modify data How to prevent it ? - Check access rights to UI level and server level for the requests to resources. - Deny access by default  

Página 5

Security Misconfiguration   What it is ? Human mistake of misconfigurating the system Impact ? Depends on misconfiguration. worst misconfiguration can result in loss of data. How to prevent it ? - Force change of default credentials - Least privilege to system - Static code that scan code for default settings - Keep patching, updating and testing the system - Regularly audit system deployment in production.

Página 6

Sensitive Data Exposure   What it is ? Sensitive data is exposed eg, social security number, passwords, health records. Impact ? Data that is lost, corrupted or exposed have serious implications on business continuity. How to prevent it ? - Always obscure data. - update cryptographic algorithm - use salted encryption on storage of passwords

Semelhante

Contraception
Matthew Coulson
1.5 Application and Security Controls
DJ Perrone
Diesel Injection Pumps
Paul Allen
Phrasal Verbs - Inglês #9
Eduardo .
Conjunções
GoConqr suporte .
Fontes e princípios do direito do trabalho
Natthan Réryson
CEJA VIRTUAL - FASCÍCULO 1 - UNIDADE 1 - CULTURA E IDENTIDADE
Hilário Jr
Função do 2º grau
Marcos do Help
Questões SUS - ANVISA
Thiago Ferreira
Lei 8112/90 (Parte I)
Maria José
PLANEJAMENTO DE LÍNGUA PORTUGUESA 2018 - 2ª ETAPA
Adriana Marcia Couto Poletti