What security issues should I consider when coding?

I know that SQL Injection is one thing ... that the other ...

+3
source share
15 answers

OWASP.org maintains a list. Start with the top ten OWASP .

+18
source

Others said it, but ...

Essentially all security vulnerabilities come from data. If your program does not process any data, it can be safe. It can also be pretty useless :).

This leads to what I consider to be the basic concept for ensuring code security:

Do not trust your data. Ever.

, . (, , , Java #), , .

+11

. ( , , , , - , . CRM: " , , Enterprise Manager Query Analyzer ?" )

+6

10 . , . , , № 8, " ".

+3

.

.

-R

+2

, C, .

+1

-, ...

JavaScript-. - - , -, JavaScript JavaScript, , ( /), javascript.

+1

...

19

+1

. /// " ? , ? , ". ; . , , . - , . .

, String , : " , ?" if-else , .

+1

. , , . , dev. , . .:)

+1

: 19

, , . - , .

+1
source

Sending plain text passwords without first encrypting them is never a good idea.

0
source

Avoid sending plain text names.

0
source

how about checking user input? For example, you expect a 10-digit phone number, but you get "800OHNOES!"

0
source

In addition to the great OWASP tutorial, also check out SANS / CWE.

0
source

Source: https://habr.com/ru/post/1699110/


All Articles