Experts Round Table Network

Web Technologies => General Web Dev => Topic started by: rdivilbiss on November 22, 2007, 03:19:44 PM



Title: MUST READ for web developers
Post by: rdivilbiss on November 22, 2007, 03:19:44 PM
Web Application Security Consortium (WASC) Web Application Security Statistics Project. http://webappsec.org/projects/statistics/ (http://webappsec.org/projects/statistics/)

And the OWASP Top 10 http://www.owasp.org/images/e/e8/OWASP_Top_10_2007.pdf (http://www.owasp.org/images/e/e8/OWASP_Top_10_2007.pdf)


Title: Re: MUST READ for web developers
Post by: CrYpTiC_MauleR on November 22, 2007, 07:11:04 PM
I don't see CSRF on the stats, it is even more widespread that XSS seeing almost every site suffers from it unless the developer took precautions to protect all HTTP requests by using checksum or requiring re-authentication for certain actions.