Mike's Security Cabinet

A place to discuss application security and related topics.

Monday, February 1, 2010

Application security resources

OWASP Prevention Cheat Sheet
  • Authentication Cheat Sheet
  • XSS (Cross Site Scripting) Prevention Cheat Sheet
  • Injection Prevention Cheat Sheet
  • SQL Injection Prevention Cheat Sheet
  • Transport Layer Protection Cheat Sheet
  • Cross-Site Request Forgery (CSRF) Prevention Cheat Sheet
  • Cryptographic Storage Cheat Sheet

  • OWASP TOP Ten Project
    http://www.owasp.org/index.php/Category:OWASP_Top_Ten_Project

    OWASP Code review Project
    http://www.owasp.org/index.php/Category:OWASP_Code_Review_Project

    OWASP Testing Project
    http://www.owasp.org/index.php/Category:OWASP_Testing_Project


    OWASP Development Guidance Project
    http://www.owasp.org/index.php/Category:OWASP_Guide_Project


    CWE/SANS TOP 25 Most Dangerous Programming Errors:
    http://www.sans.org/top25-programming-errors/



    Posted by michael xin at 9:49 PM

    No comments:

    Post a Comment

    Newer Post Older Post Home
    Subscribe to: Post Comments (Atom)

    About Me

    michael xin
    CISSP, Application security engineer with interest in penetration testing, security application development, mobile security.
    View my complete profile

    Blog Archive

    • ►  2013 (9)
      • ►  March (3)
      • ►  February (6)
    • ►  2012 (25)
      • ►  October (1)
      • ►  August (1)
      • ►  June (1)
      • ►  May (4)
      • ►  April (3)
      • ►  March (9)
      • ►  February (6)
    • ►  2011 (4)
      • ►  November (2)
      • ►  April (2)
    • ▼  2010 (23)
      • ►  August (1)
      • ►  July (6)
      • ►  May (6)
      • ►  March (1)
      • ▼  February (7)
        • AppSec Challenge 9's solution
        • Some interview techniques
        • AppSec Research Challenge 9: Crack 'Em Hashes
        • How to test Flash Application
        • How to use urlEncode to encode Request.Url?
        • Application security resources
        • Microsoft .NET security resources
      • ►  January (2)
    Simple theme. Powered by Blogger.