官术网_书友最值得收藏!

OWASP testing guide

The Open Web Application Security Project (OWASP) is an open source community project that develops software tools and knowledge-based documentation that helps people secure web applications and web services. OWASP is an open source reference point for system architects, developers, vendors, consumers, and security professionals involved in designing, developing, deploying, and testing the security of web applications and web Services. In short, the OWASP aims to help everyone and anyone to build more secure web applications and web services. One of the best aspects of the OWASP testing guide is its comprehensive description of determining the business risk presented by findings. The OWASP testing guide rates risk based on the impact it could have to the business, and the chance it will occur. By those aspects described in the OWASP testing guide, the overall risk rating of a given finding can be found out, which gives the organization appropriate guidance based on the result of their findings.
The OWASP testing guide primarily focuses on the following:

  • Techniques and tools in web-application testing
  • Information-gathering
  • Authentication testing
  • Business logic testing
  • Data-validation testing
  • Denial-of-service attack testing
  • Session-management testing
  • Web services testing
  • AJAX testing
  • Risk severity
  • Likely hood of risk
主站蜘蛛池模板: 丰县| 贡山| 葫芦岛市| 馆陶县| 合江县| 东乡| 裕民县| 罗平县| 高安市| 安仁县| 耒阳市| 牙克石市| 广德县| 石棉县| 广元市| 钟山县| 佛坪县| 周口市| 张家港市| 高安市| 广河县| 都兰县| 六盘水市| 石阡县| 永仁县| 都安| 洞头县| 福安市| 登封市| 龙山县| 图们市| 大港区| 兴仁县| 抚州市| 北海市| 连云港市| 通榆县| 长沙市| 葵青区| 旺苍县| 吉木萨尔县|