|
|||||||||||
|
OWASP Identifies Ten Most Critical Web Application Security Vulnerabilities
From: Jeff Williams (at) Aspect <(at)>
Date: Sun Jan 12 2003 - 23:32:38 EST
FOR IMMEDIATE RELEASE OWASP Identifies Ten Most Critical Web Application Security Vulnerabilities Washington, D.C. -- A new report detailing the ten most critical web application security problems was unveiled today by the Open Web Application Security Project. OWASP is dedicated to helping organizations understand and improve the security of their web applications and web services. Download the report from the OWASP website at http://www.owasp.org. "The OWASP Top Ten list shines a spotlight directly on one of the most
These flaws are surprisingly common and can be exploited by unsophisticated attackers with easily available tools. When an organization deploys a web application, they invite the world to send HTTP requests. Attacks buried in these requests sail past firewalls, filters, platform hardening, SSL, and IDS without notice because they are inside legal HTTP requests. Therefore, web application code is part of the security perimeter and cannot be ignored. "This list is an important development for consumers and vendors alike,"
"This 'Ten-Most-Wanting' List acutely scratches at the tip of an enormous
The Open Web Application Security Project (OWASP) is an Open Source community project staffed entirely by volunteer experts from across the world. Project chair Mark Curphey said, "the OWASP Top Ten Project was formed to capture our collective wisdom and present it in a way that would bring the attention web application security deserves." Questions or comments about the OWASP Top Ten should be sent to: topten@owasp.org
Contacts:
--Jeff
Jeff Williams, CEO
This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:07:47 EDT |
||||||||||
|
|||||||||||