The Security Learning
The Security Learning
P:Prevalence
W:Weakness Detectability
I:Impact
1 OWASP
A Injection:SQL,OS,LDAP injection. (P:common,W:Average,I:Severe)
B Cross-Site Scripting (XSS)(P:Very WideSpread, W:Easy,I:Moderate):惡意攻擊者往Web頁(yè)面里插入惡意html代碼,當(dāng)用戶瀏覽該頁(yè)之時(shí),嵌入其中Web里面的html代碼會(huì)被執(zhí)行,從而達(dá)到惡意用戶的特殊目的。
C Broken Authentication and Session Management.(P:COMMON,W:AVERAGE,I:SEVERE)
D Insecure Direct Object References.(P:COMMON,W:EASY,I:SEVERE)
E Cross-site Request Forgery:跨站請(qǐng)求偽造 (P:Widespread,W:EASY,I:MODERATE)
F Security Misconfiguration:(P:COMMON,W:EASY,I:MODERATE)
G Insecure Cryptographic storage:(P:UNCOMMON,W:DIFFICULT,I:SEVERE)
H Failure to Restrict URL ACCESS (P:UNCOMMON,W:AVERAGE,I:MODERATE)
I Insufficient Transport Layer Protection (P:COMMON,W:EASY,I:MODERATE)
J Unvalidated Redirects and Forwards (P:UNCOMMON,W:EASYI:MODERATE)
2 Secure Implementation Principles
SDL:Secure Development Lifecycle
轉(zhuǎn)載于:https://www.cnblogs.com/SoulSpirit/p/3332956.html
總結(jié)
以上是生活随笔為你收集整理的The Security Learning的全部?jī)?nèi)容,希望文章能夠幫你解決所遇到的問(wèn)題。
- 上一篇: 去车开新卖车要注意点什么?
- 下一篇: 胡迪克斯瓦尔机场可以还车吗?