Free Book on Building Secure Web Applications免费书籍就构建安全Web应用程序
The Open Web Application Security Project (开放Web应用安全项目( OWASP.org owasp.org ) has written and )已书面和 published出版 a free 293-page book detailing how to build and develop Secure Web Applications.免费的293页的书,详细说明如何建立和发展安全的Web应用程序。 This guide carefully explains many common web security issues, such as cross site scripting and SQL injection vulnerabilities.本指南仔细解释,有许多共同的Web安全问题,如跨站点脚本和SQL注入漏洞。 It provides information about securing most forms of web applications and services, along with real world guidance using J2EE,它提供的信息,确保大多数形式的Web应用程序和服务,随着现实世界中使用J2EE的指导, ASP.NET asp.net , and PHP samples. ,和PHP的样本。 It also discusses Microsoft's Threat Risk Modeling strategy, as well as several other security methodologies, such as Trike, CVSS, AS4360, and Octave.它还讨论了微软的威胁,风险建模策略,以及其他几个安全的方法,如trike , cvss , as4360 ,八度。 Here is a这里是一个 zip download of the guide邮编下载指南 . OWASP also provides some excellent 。 owasp也提供了一些优秀的 Web Security Presentations Web安全演示 and和 Web Security Papers Web安全文件 . 。
A Guide to Building Secure Web Applications and Web Services 指南构建安全Web应用程序和Web服务
(3.1mb, pdf format) ( 3.1mb , PDF格式)
Table of Contents 目录
- About The Open Web Application Security Project关于开放Web应用安全项目
- Introduction导言
- What Are Web Applications?什么是Web应用程序?
- Security Architecture And Design安全体系结构和设计
- Secure Coding Principles安全编码原则
- Threat Risk Modeling威胁的风险建模
- Handling E-Commerce Payments处理电子商务支付系统
- Phishing网络钓鱼
- Web Services Web服务
- Authentication验证
- Authorization授权
- Session Management会议管理
- Data Validation数据验证
- Interpreter Injection口译注射液
- Canoncalization, Locale And Unicode canoncalization ,区域设置和Unicode
- Error Handling, Auditing And Logging错误处理,审计和日志记录
- File System文件系统
- Buffer Overflows缓冲区溢出
- Administrative Interfaces行政接口
- Cryptography加密技术
- Configuration配置
- Maintenance维修
- Denial Of Service Attacks拒绝服务攻击
- Gnu Free Documentation License在GNU自由文档许可证
- Php Guidelines PHP的指引
- Cheat Sheets作弊表
Technorati Tags: Technorati标记: web security Web安全 , , secure web applications安全Web应用程序 , , secure applications安全应用 , , secure progamming安全编程
Popularity: 39% [人气: 39 % [ ? ? ] ]
Related Posts: 相关文章:





















