« More on the smartcard story - a solution | Main | Question on complex passwords »

OWASP

OWASP, for those of you who don't know, stands for Open Web Application Security Project. It's a long established open source resource committed to improving web product security. I've long been enthusiastic about the project and some of the excellently produced tools and documentation that have come out of it. I recommend that anyone involved in any aspect of web product development takes a look.It's right here at www.owasp.org.

The project has just release a new version of it's guide to the top ten web application vulnerabilities. It's a very informative, useful, and above all, relevant document. I can guarantee that every vulnerability test that you perform will report back one or more of the issues highlighted in this work. You can download the document from the OWASP site.

Mark Curphey, one of the originators of OWASP has his own blog at securitybuddha.com. I also recommend this as a good stop-off when you have a few minutes to spare - obviously after reading this blog first.

TrackBack

TrackBack URL for this entry:
http://www.computerweekly.com/cgi-bin/mt/mt-tb.cgi/2867

Post a comment

(If you haven't left a comment here before, you may need to be approved by the site owner before your comment will appear. Until then, it won't appear on the entry. Thanks for waiting.)

About

This page contains a single entry from the blog posted on February 1, 2007 8:00 AM.

The previous post in this blog was More on the smartcard story - a solution.

The next post in this blog is Question on complex passwords.

Many more can be found on the main index page or by looking through the archives.