Web Application Security Guide/Checklist

< Web Application Security Guide

Miscellaneous points

File inclusion and disclosure

File upload vulnerabilities

SQL injection

Cross-site scripting (XSS)

XML and internal data escaping

XML, JSON and general API security

(Un)trusted input

Cross-site request forgery (CSRF)

Clickjacking

Insecure data transfer

Session fixation

Session stealing

Truncation attacks, trimming attacks

Password security

Comparison issues

PHP-specific issues

Prefetching and Spiders

Special files

SSL, TLS and HTTPS basics

  1. Patrick Mylund Nielsen. "Storing Passwords Securely".
  2. Wikibook Cryptography/Secure Passwords describes more of the history and theory behind designing a hashing algorithm for password storage.
This article is issued from Wikibooks. The text is licensed under Creative Commons - Attribution - Sharealike. Additional terms may apply for the media files.