官术网_书友最值得收藏!

OWASP testing guide

The Open Web Application Security Project (OWASP) is an open source community project that develops software tools and knowledge-based documentation that helps people secure web applications and web services. OWASP is an open source reference point for system architects, developers, vendors, consumers, and security professionals involved in designing, developing, deploying, and testing the security of web applications and web Services. In short, the OWASP aims to help everyone and anyone to build more secure web applications and web services. One of the best aspects of the OWASP testing guide is its comprehensive description of determining the business risk presented by findings. The OWASP testing guide rates risk based on the impact it could have to the business, and the chance it will occur. By those aspects described in the OWASP testing guide, the overall risk rating of a given finding can be found out, which gives the organization appropriate guidance based on the result of their findings.
The OWASP testing guide primarily focuses on the following:

  • Techniques and tools in web-application testing
  • Information-gathering
  • Authentication testing
  • Business logic testing
  • Data-validation testing
  • Denial-of-service attack testing
  • Session-management testing
  • Web services testing
  • AJAX testing
  • Risk severity
  • Likely hood of risk
主站蜘蛛池模板: 鄱阳县| 武冈市| 南开区| 大名县| 菏泽市| 安新县| 读书| 鲁山县| 曲麻莱县| 阳泉市| 滨州市| 九寨沟县| 西丰县| 桐柏县| 来宾市| 通山县| 江北区| 衡山县| 清水河县| 修武县| 鄢陵县| 西峡县| 长海县| 上虞市| 疏勒县| 宾阳县| 阜南县| 黑山县| 云浮市| 盐山县| 六枝特区| 博白县| 左权县| 翁源县| 泰兴市| 香格里拉县| 滦平县| 大新县| 西乡县| 抚顺市| 西乌珠穆沁旗|