Getting started with Web application misuse cases
Submitted By: SearchSoftwareQuality.com | 17 Apr 2008 TIP - When developing applications it isn't enough to think about how they will be used. You must also consider how they will be misused -- or abused -- so that you can prevent attacks.
The essentials of Web application threat modeling
Submitted By: SearchSoftwareQuality.com | 24 Mar 2008 TIP - A critical part of Web application security is mapping out what's at risk -- or threat modeling. Kevin Beaver outlines the essential steps to get you started.
How to prevent XPath injection
Submitted By: SearchSoftwareQuality.com | 11 Feb 2008 TIP - Parameterization and input validation are invaluable to application security. Which method is best for preventing XPath injection attacks? Expert Chris Eng explains.
Web application hacking: Inside the mind of an attacker
Submitted By: SearchSoftwareQuality.com | 15 Jan 2008 TIP - Want to prevent your Web app from being hacked? Then you need to think like an attacker. Kevin Beaver helps you change your mindset so you think about how your app can be misused.
How to define the scope of functional security testing
Submitted By: SearchSoftwareQuality.com | 18 Dec 2007 TIP - With a many internal threats originating from applications, functional security testing is one of the most reliable ways to identify internal security vulnerabilities.
Cracking passwords the Web application way
Submitted By: SearchSoftwareQuality.com | 17 Dec 2007 TIP - Don't think your Web application is secure just because it uses SSL. If you don't have proper login controls in place, attackers can crack passwords and get in.
Involve the security team in software security testing
Submitted By: SearchSoftwareQuality.com | 27 Nov 2007 TIP - By involving security experts in code reviews and testing you will make sure all security requirements are met.
How to get developers to buy into software security
Submitted By: SearchSoftwareQuality.com | 19 Nov 2007 TIP - Getting developers' buy-in on security and secure coding practices can be like pulling teeth. But Kevin Beaver has some ideas to get them to follow security practices.
Eight reasons to do source code analysis on your Web application
Submitted By: SearchSoftwareQuality.com | 16 Oct 2007 TIP - Source code analysis may sound like a difficult, expensive task. The truth is it's a relatively easy way to ensure your Web application is secure and to reduce business risk.
What to do after penetration testing: source code analysis
Submitted By: SearchSoftwareQuality.com | 22 Aug 2007 TIP - You may think penetration testing is enough to make sure your Web sites are secure. But source code analysis tools can uncover vulnerabilities not easily found using pen testing.
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.