Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



WebApp Sec: A Modular Approach to Data Validation in Web Applications

A Modular Approach to Data Validation in Web Applications

From: Stephen de Vries <stephen_at_corsaire.com>
Date: Mon, 27 Mar 2006 17:43:33 +0700

A Corsaire White Paper:

A Modular Approach to Data Validation in Web Applications

Outline:

Data that is not validated or poorly validated is the root cause of a
number of serious security vulnerabilities affecting applications.
This paper presents a modular approach to performing thorough data
validation in modern web applications so that the benefits of modular
component based design; extensibility, portability and re-use, can be
realised. It starts with an explanation of the vulnerabilities
introduced through poor validation and then goes on to discuss the
merits and drawbacks of a number of common data validation strategies
such as:
- Validation in an external Web Application Firewall;
- Validation performed in the web tier (e.g. Struts); and
- Validation performed in the domain model.
Finally, a modular approach is introduced together with practical
examples of how to implement such a scheme in a web application.

Download:

http://www.corsaire.com/white-papers/060116-a-modular-approach-to-
data-validation.pdf

-------------------------------------------------------------------------
This List Sponsored by: SpiDynamics

ALERT: "How A Hacker Launches A Web Application Attack!"
Step-by-Step - SPI Dynamics White Paper
Learn how to defend against Web Application Attacks with real-world
examples of recent hacking methods such as: SQL Injection, Cross Site
Scripting and Parameter Manipulation

https://download.spidynamics.com/1/ad/web.asp?Campaign_ID=701300000003gRl
--------------------------------------------------------------------------
Received on Mar 27 2006

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos