Top 10 Vulnerabilities in Web Applications
sverrehu writes "The Open Web Application Security
Project (OWASP) has released a well-written document that is a
must read for every web programmer out there. This security document
is not about firewalls, encryption and patching. It's about common,
highly exploitable errors made by the application programmers. Pick
up your copy of "The Ten Most Critical Web Application Security
Vulnerabilities" from the OWASP web site."
The only safe web server is an un-installed web server.
Microsoft .NET and IIS.
Karma: The shiznight, mostly because I am the Drizzle.
"I like my web servers just like my women...insecure and full of holes waiting to be exploited." --Bill G.
Ya, but it's missing...
.NET
11. Using
Misconfigured Users
So, you're telling me that I *shouldn't* write web apps with remote exploits, buffer overflows and generally crappy security?!?!? Well color me flabbergasted!
"In a 32-bit world, you're a 2-bit user. You've got your own newsgroup, alt.total.loser." -Weird Al
Having information potentially of interest to Slashdot.
Though I would like to see Buffy overflow every now and then.
11. Getting Slashdotted
Tuus crepidae innexilis sunt.
A11 Link on Slashdot
In spite of many alarming examples, the danger associated with having a link to your web site posted on the Slashdot front page continues to be underestimated by many developers of web applications. Neglect of this threat can cause your web server to actually burn through the floor of your computer building in a manner similar to nuclear meltdown.
New show on Fox: Buffer the overflow slayer.
so if i don't check user input, that is bad? glad i spent 10 minutes on company time getting my learn on. i'll be sure to pass this on to all of the other developers.
MARIJUANA, SHROOMS, X: ONLINE?! - E
yeah, but god is spelled 'gahd', as in sysgahd. don't you know anything about the male ego? i mean gahd damn.
You forgot:
o oooooooooooooooooooooooooooooooooooooooooooooooooo oooooooooooooooooooooooooooooooooooooooooooooooooo oooooooooooooooooooooooooooooooooooooooooooooooooo oooooooooooooooooooooooooooooooooooooooooooooooooo oooooooooows\x31\xc0\x50\x68\x2f\x2f\x73\x68\x68\x 2f\x62\x69\x6e\x89\xe3\x50\x53\x89\xe1\x31\xd2\xb0 \x0b\xcd\x80
11. Buffer Overflooooooooooooooooooooooooooooooooooooooooooo
root#
Being /.'d