|
|||||||||||
|
RES: Fail Open Authentication and Parameter Injection
From: Mads Rasmussen <mads(at)opencs.com.br>
Date: Tue Mar 25 2003 - 15:23:53 EST > -----Mensagem original-----
It would be nice if OWASP could include some general guidelines on this, I could imagine something like listing some priorities and maybe some examples of how to identify bad code > To me, the hardest problems to find are integrity issues and trojans.
You hit the soft spot, I don't have a clue as how to avoid this. If you must spend time to understand the business rule the code review becomes very time consuming and thus expensive for the client. In this outsourced world trojans seems to be an increasing risk, might be somewhat avoided be testing communication of app with a sniffer, but it won't capture all, Trojan might be time invoked Mads Received on Tue Mar 25 15:51:22 2003 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:07:49 EDT |
||||||||||
|
|||||||||||