<rt id="bn8ez"></rt>
<label id="bn8ez"></label>

  • <span id="bn8ez"></span>

    <label id="bn8ez"><meter id="bn8ez"></meter></label>

    Sealyu

    --- 博客已遷移至: http://www.sealyu.com/blog

      BlogJava :: 首頁 :: 新隨筆 :: 聯系 :: 聚合  :: 管理 ::
      618 隨筆 :: 87 文章 :: 225 評論 :: 0 Trackbacks

    On April 19, 2010 we released the final version of the OWASP Top 10 for 2010, and here is the associated press release. This version was updated based on numerous comments received during the comment period after the release candidate was released in Nov. 2009.

    The OWASP Top 10 Web Application Security Risks for 2010 are:

    • A1: Injection
    • A2: Cross-Site Scripting (XSS)
    • A3: Broken Authentication and Session Management
    • A4: Insecure Direct Object References
    • A5: Cross-Site Request Forgery (CSRF)
    • A6: Security Misconfiguration
    • A7: Insecure Cryptographic Storage
    • A8: Failure to Restrict URL Access
    • A9: Insufficient Transport Layer Protection
    • A10: Unvalidated Redirects and Forwards

    Please help us make sure every developer in the ENTIRE WORLD knows about the OWASP Top 10 by helping to spread the word!!!

    As you help us spread the word, please emphasize:

    • OWASP is reaching out to developers, not just the application security community
    • The Top 10 is about managing risk, not just avoiding vulnerabilities
    • To manage these risks, organizations need an application risk management program, not just awareness training, app testing, and remediation

    We need to encourage organizations to get off the penetrate and patch mentality. As Jeff Williams said in his 2009 OWASP AppSec DC Keynote: “we’ll never hack our way secure – it’s going to take a culture change” for organizations to properly address application security.

    If you are interested in doing a presentation on the OWASP Top 10, please feel free to use all or parts of this:

    Introduction

    The OWASP Top Ten provides a powerful awareness document for web application security. The OWASP Top Ten represents a broad consensus about what the most critical web application security flaws are. Project members include a variety of security experts from around the world who have shared their expertise to produce this list. Versions of the 2007 were translated into English, French, Spanish, Japanese, Korean and Turkish and other languages. Translation efforts for the 2010 version are underway and they will be posted as they become available.

    We urge all companies to adopt this awareness document within their organization and start the process of ensuring that their web applications do not contain these flaws. Adopting the OWASP Top Ten is perhaps the most effective first step towards changing the software development culture within your organization into one that produces secure code.

    posted on 2010-11-21 20:06 seal 閱讀(368) 評論(0)  編輯  收藏 所屬分類: 系統架構
    主站蜘蛛池模板: 久久久高清免费视频 | 成年午夜视频免费观看视频| 亚洲欧洲国产综合AV无码久久| 日产国产精品亚洲系列| 十八禁在线观看视频播放免费| 亚洲性无码av在线| 免费人成在线观看网站品爱网日本| 成全视频在线观看免费| 一本色道久久88—综合亚洲精品| 久久精品国产亚洲5555| 无码av免费毛片一区二区| 亚洲黄片手机免费观看| 亚洲日本一线产区和二线 | 亚洲乱人伦中文字幕无码| 国产亚洲一区区二区在线| 无码av免费毛片一区二区| 中文无码日韩欧免费视频| 亚洲熟妇无码一区二区三区| 亚洲精品乱码久久久久久久久久久久| 猫咪社区免费资源在线观看 | 一级毛片在线免费看| 成人婷婷网色偷偷亚洲男人的天堂| 亚洲嫩模在线观看| 亚洲国产精品国产自在在线| 四虎永久在线观看免费网站网址| 国产免费内射又粗又爽密桃视频| 亚洲国产区男人本色| 亚洲高清视频在线播放| 国产成人亚洲精品狼色在线| 成人国产mv免费视频| 1000部啪啪未满十八勿入免费| A毛片毛片看免费| 一区二区免费在线观看| 亚洲中文字幕乱码一区| 亚洲精品日韩专区silk | 亚洲a∨无码一区二区| 亚洲成综合人影院在院播放| 亚洲国产精品无码久久一区二区| 亚洲成人高清在线| 国产又粗又长又硬免费视频| 成人免费看片又大又黄|