While they're described with such obscure names as Cross-Site Scripting, SQL Injection, or directory transversal, mitigating the risks associated with web application vulnerabilities and the attack methods that exploit them needn't be beyond the reach of any organization. This article, the first in a three-part series, will provide an overview of what you need to know to perform a vulnerability assessment to check for web security risks. It'll show you what you can reasonably expect a web application security scanner to accomplish, and what types of assessments still require expert eyes. The following two articles will show you how to remedy the web security risks a vulnerability assessment will uncover (and there'll be plenty to do), and the final segment will explain how to instill the proper levels of awareness, policies, and technologies required to keep web application security flaws to a minimum - from an application's conception, design, and coding, to its life in production.
Web Application Vulnerability Assessment Essentials
- Learn How to Properly Execute a Web Application Vulnerability Assessment
- Just What Is a Web Application Vulnerability Assessment?
- Conducting Your Vulnerability Assessment: The First Steps
- The Vulnerability Assessment
Learn How to Properly Execute a Web Application Vulnerability Assessment
You might also like...
About the author
Caleb Sima
Caleb Sima is the former co-founder and CTO of SPI Dynamics, which was acquired by HP Software...
Open Source tutorials
- What You Need to Know about PCI Compliance and Web Application Security Policy Changes
- Effective Controls for Attaining Continuous Application Security Throughout the Web Application Development Life Cycle
- Top 10 Application Security Vulnerabilities in Web.config Files - Part Two
- Testing for Security in the Age of Ajax Programming
Open Source books
-
Computer Security Fundamentals (2nd Edition)
Welcome to today’s most useful and practical one-volume introduction to computer security. Chuck Easttom brings together up-to-the-minute coverage of all basic concepts, terminology, and issues, along with all the skills you need to get started in th...
Open Source forum discussion
-
How to log in and download from a website
by blackjack (0 replies)
-
how to secure application against piracy?
by gratisappels (0 replies)
-
Capabilities of HTML5
by berramelon_bliss (0 replies)
-
Click through code
by TrishB (0 replies)
-
How to Freeware to Extract MP3 from QuickTime MOV
by ellefish310 (0 replies)
Open Source podcasts
-
Security Now: Security Now 329
Published 1 month ago, running time 0h0m
BrowserID Hosts: Steve Gibson with Leo LaporteComparing Mozilla's BrowserID to other security technologies, Android malware, Malvertising, and more.Download or subscribe to this show at twit.tv/sn.We invite you to read, add to, and amend our show notes.For 16kpbs versions
Open Source events
-
Feb
15
Attend virtual event "Clouds, Outsourcing, and Security Services"
Farmers Branch, United States
Feb 15th, 0930AM CST (Call will be available to registered attendees after this date and time) Registration Site: https://www.techwebon... Prsentation Title: Making Providers a Part of your IT Security Strategy While attending this presentation prepare to learn about and and retain knowledge pertaining to the following six topics # List key security questions to ask a potential cloud services provider # Identify the potential vulnerabilities introduced by cloud services - and describe how to avo
This space has come a long way since the original post. Application penetration testing is a specialist area which has evolved considerably over the last few years. The OWASP guidelines are probably the best reference for application developers. However, the final penetration test should really be done by suitably qualified experts.
!--removed tag-->