Quick intro to auditing web applications.
Last time I taught the web application security workshop, students asked for a brief guide to assess their own web applications for common problems. So I sat down and wrote up a little paper outlining how I typically go about when I try to take a quick look at a web application. Sadly, while this is a very quick and incomplete "audit", many web apps I am asked to look at fail.
For the complete article see: www.sans.edu/resources/securitylab/audit_web_apps.php .
(While you are there... take a look at the Leadership and Security lab links at the top of the page for more articles)
And for all ISC/ DShield users: I will be in San Diego in two weeks to teach the Linux/Apache/MySQL/PHP class. If you happen to be at SANS 2007: We will probably have a BoF session. Watch the announcements for details.
For the complete article see: www.sans.edu/resources/securitylab/audit_web_apps.php .
(While you are there... take a look at the Leadership and Security lab links at the top of the page for more articles)
And for all ISC/ DShield users: I will be in San Diego in two weeks to teach the Linux/Apache/MySQL/PHP class. If you happen to be at SANS 2007: We will probably have a BoF session. Watch the announcements for details.
Keywords:
0 comment(s)
My next class:
Application Security: Securing Web Apps, APIs, and Microservices | Washington | Dec 13th - Dec 18th 2024 |
×
Diary Archives
Comments