<rt id="bn8ez"></rt>
<label id="bn8ez"></label>

  • <span id="bn8ez"></span>

    <label id="bn8ez"><meter id="bn8ez"></meter></label>

    Sealyu

    --- 博客已遷移至: http://www.sealyu.com/blog

      BlogJava :: 首頁 :: 新隨筆 :: 聯(lián)系 :: 聚合  :: 管理 ::
      618 隨筆 :: 87 文章 :: 225 評論 :: 0 Trackbacks

    On April 19, 2010 we released the final version of the OWASP Top 10 for 2010, and here is the associated press release. This version was updated based on numerous comments received during the comment period after the release candidate was released in Nov. 2009.

    The OWASP Top 10 Web Application Security Risks for 2010 are:

    • A1: Injection
    • A2: Cross-Site Scripting (XSS)
    • A3: Broken Authentication and Session Management
    • A4: Insecure Direct Object References
    • A5: Cross-Site Request Forgery (CSRF)
    • A6: Security Misconfiguration
    • A7: Insecure Cryptographic Storage
    • A8: Failure to Restrict URL Access
    • A9: Insufficient Transport Layer Protection
    • A10: Unvalidated Redirects and Forwards

    Please help us make sure every developer in the ENTIRE WORLD knows about the OWASP Top 10 by helping to spread the word!!!

    As you help us spread the word, please emphasize:

    • OWASP is reaching out to developers, not just the application security community
    • The Top 10 is about managing risk, not just avoiding vulnerabilities
    • To manage these risks, organizations need an application risk management program, not just awareness training, app testing, and remediation

    We need to encourage organizations to get off the penetrate and patch mentality. As Jeff Williams said in his 2009 OWASP AppSec DC Keynote: “we’ll never hack our way secure – it’s going to take a culture change” for organizations to properly address application security.

    If you are interested in doing a presentation on the OWASP Top 10, please feel free to use all or parts of this:

    Introduction

    The OWASP Top Ten provides a powerful awareness document for web application security. The OWASP Top Ten represents a broad consensus about what the most critical web application security flaws are. Project members include a variety of security experts from around the world who have shared their expertise to produce this list. Versions of the 2007 were translated into English, French, Spanish, Japanese, Korean and Turkish and other languages. Translation efforts for the 2010 version are underway and they will be posted as they become available.

    We urge all companies to adopt this awareness document within their organization and start the process of ensuring that their web applications do not contain these flaws. Adopting the OWASP Top Ten is perhaps the most effective first step towards changing the software development culture within your organization into one that produces secure code.

    posted on 2010-11-21 20:06 seal 閱讀(370) 評論(0)  編輯  收藏 所屬分類: 系統(tǒng)架構(gòu)
    主站蜘蛛池模板: 国产免费私拍一区二区三区| 国产精品亚洲аv无码播放| 激情小说亚洲色图| 亚洲日本中文字幕天堂网| 成人爽a毛片免费| 亚洲久悠悠色悠在线播放| 毛片a级毛片免费播放下载| 亚洲国产成人精品无码久久久久久综合 | 亚洲黑人嫩小videos| 日韩一区二区免费视频| 成人A片产无码免费视频在线观看| 亚洲女人18毛片水真多| 亚洲欧洲自拍拍偷精品 美利坚| 久久久久久夜精品精品免费啦| 亚洲国产精品无码久久久秋霞1 | 亚洲乱人伦精品图片| 亚洲男人av香蕉爽爽爽爽| 成人免费的性色视频| 国产线视频精品免费观看视频| 亚洲性色AV日韩在线观看| 亚洲熟妇无码AV在线播放| 免费看AV毛片一区二区三区| 亚洲视频免费在线观看| 国产精品日本亚洲777| 亚洲国产精品乱码在线观看97| 亚洲人成无码网WWW| 成人免费午间影院在线观看| 午夜免费福利小电影| 日韩少妇内射免费播放| 亚洲午夜无码久久| 日韩精品一区二区亚洲AV观看| 在线观看亚洲精品国产| 国产嫩草影院精品免费网址| 99无码人妻一区二区三区免费| 国产一级淫片a免费播放口| 一进一出60分钟免费视频| 亚洲AⅤ男人的天堂在线观看 | 国产99在线|亚洲| 久久久婷婷五月亚洲97号色| 亚洲一区二区女搞男| 亚洲国产午夜中文字幕精品黄网站|