<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Benfellows</id>
		<title>OWASP - User contributions [en]</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Benfellows"/>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php/Special:Contributions/Benfellows"/>
		<updated>2026-04-03T19:55:17Z</updated>
		<subtitle>User contributions</subtitle>
		<generator>MediaWiki 1.27.2</generator>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:Benfellows&amp;diff=25968</id>
		<title>User:Benfellows</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:Benfellows&amp;diff=25968"/>
				<updated>2008-02-25T17:13:44Z</updated>
		
		<summary type="html">&lt;p&gt;Benfellows: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Hi, my name is Ben Fellows.  I work as an IT Security Risk Consultant for [http://www.ey.com/global/content.nsf/International/AABS_-_RAS_-_TSRS Ernst &amp;amp; Young's Technology and Security Risk Services] group, under the Risk Advisory Services umbrella, here in Denver, CO.  Drop me a line, I would love to chat.&lt;br /&gt;
{{user new message|Benfellows}}&lt;/div&gt;</summary>
		<author><name>Benfellows</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:Benfellows&amp;diff=25862</id>
		<title>User:Benfellows</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:Benfellows&amp;diff=25862"/>
				<updated>2008-02-22T19:34:49Z</updated>
		
		<summary type="html">&lt;p&gt;Benfellows: adding new message template&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Hi, my name is Ben Fellows.  I work as an IT Security Risk Consultant for [http://www.ey.com/global/content.nsf/International/AABS_-_RAS_-_TSRS Ernst &amp;amp; Young's Technology and Security Risk Services] group, under the Risk Advisory Services umbrella.  Drop me a line, I would love to chat.&lt;br /&gt;
{{user new message|Benfellows}}&lt;/div&gt;</summary>
		<author><name>Benfellows</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Template:User_new_message&amp;diff=25861</id>
		<title>Template:User new message</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Template:User_new_message&amp;diff=25861"/>
				<updated>2008-02-22T19:33:59Z</updated>
		
		<summary type="html">&lt;p&gt;Benfellows: fix&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;div style=&amp;quot;align: center; padding: 1em; border: solid 1px {{{bordercolor|#1874cd}}}; background-color: {{{color|#d1eeee}}};&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;'''Please click &amp;lt;span class=&amp;quot;plainlinks&amp;quot;&amp;gt;[{{fullurl:User_talk:{{{name|{{PAGENAME}}}}}|action=edit&amp;amp;section=new}} &amp;lt;font color=&amp;quot;002b88&amp;quot;&amp;gt;here&amp;lt;/font&amp;gt;]&amp;lt;/span&amp;gt; to leave me a new message.'''&amp;lt;/center&amp;gt;&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;noinclude&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;Add this to your page using the following code: '''&amp;lt;code&amp;gt;{&amp;amp;#123;user new message|color=''COLOR OF BOX''|bordercolor=''COLOR OF BORDER''|name=''USERNAME''}}&amp;lt;/code&amp;gt;'''. If you do not include the ''color'', ''bordercolor'' and ''name'' parameters, the background and border will by default take the blue colour, as displayed here, and the name as the '''&amp;lt;code&amp;gt;{{&amp;amp;#123;PAGENAME}}}&amp;lt;/code&amp;gt;'''&lt;br /&gt;
&amp;lt;/noinclude&amp;gt;&lt;/div&gt;</summary>
		<author><name>Benfellows</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Template:User_new_message&amp;diff=25860</id>
		<title>Template:User new message</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Template:User_new_message&amp;diff=25860"/>
				<updated>2008-02-22T19:33:10Z</updated>
		
		<summary type="html">&lt;p&gt;Benfellows: creating template&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;div style=&amp;quot;align: center; padding: 1em; border: solid 1px {{{bordercolor|#1874cd}}}; background-color: {{{color|#d1eeee}}};&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;'''Please click &amp;lt;span class=&amp;quot;plainlinks&amp;quot;&amp;gt;[{{fullurl:User_talk:{{{name|{{PAGENAME}}}}}|action=edit&amp;amp;section=new}} &amp;lt;font color=&amp;quot;002b88&amp;quot;&amp;gt;here&amp;lt;/font&amp;gt;]&amp;lt;/span&amp;gt; to leave me a new message.'''&amp;lt;/center&amp;gt;&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;noinclude&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;Add this to your page using the following code: '''&amp;lt;code&amp;gt;{&amp;amp;#123;user new message|color=''COLOR OF BOX''|bordercolor=''COLOR OF BORDER''|name=''USERNAME''}}&amp;lt;/code&amp;gt;'''. If you do not include the ''color'', ''bordercolor'' and ''name'' parameters, the background and border will by default take the blue colour, as displayed here, and the name as the '''&amp;lt;code&amp;gt;{{&amp;amp;#123;PAGENAME}}}&amp;lt;/code&amp;gt;'''&lt;/div&gt;</summary>
		<author><name>Benfellows</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User_talk:Benfellows&amp;diff=25859</id>
		<title>User talk:Benfellows</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User_talk:Benfellows&amp;diff=25859"/>
				<updated>2008-02-22T19:32:21Z</updated>
		
		<summary type="html">&lt;p&gt;Benfellows: New page: &amp;lt;noinclude&amp;gt;{{user new message|name=Benfellows}} &amp;lt;/noinclude&amp;gt;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;noinclude&amp;gt;{{user new message|name=Benfellows}}&lt;br /&gt;
&amp;lt;/noinclude&amp;gt;&lt;/div&gt;</summary>
		<author><name>Benfellows</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:Benfellows&amp;diff=25745</id>
		<title>User:Benfellows</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:Benfellows&amp;diff=25745"/>
				<updated>2008-02-21T23:24:20Z</updated>
		
		<summary type="html">&lt;p&gt;Benfellows: wikify&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Hi, my name is Ben Fellows.  I work as an IT Security Risk Consultant for [http://www.ey.com/global/content.nsf/International/AABS_-_RAS_-_TSRS Ernst &amp;amp; Young's Technology and Security Risk Services] group, under the Risk Advisory Services umbrella.  Drop me a line, I would love to chat.&lt;/div&gt;</summary>
		<author><name>Benfellows</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:Benfellows&amp;diff=25744</id>
		<title>User:Benfellows</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:Benfellows&amp;diff=25744"/>
				<updated>2008-02-21T23:22:03Z</updated>
		
		<summary type="html">&lt;p&gt;Benfellows: creating page&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Hi, my name is Ben Fellows.  I work as an IT Security Risk Consultant for Ernst &amp;amp; Young's Risk Advisory Services.  Drop me a line, I would love to chat.&lt;/div&gt;</summary>
		<author><name>Benfellows</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Guia_Tabla_de_Contenido&amp;diff=25743</id>
		<title>Guia Tabla de Contenido</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Guia_Tabla_de_Contenido&amp;diff=25743"/>
				<updated>2008-02-21T23:05:58Z</updated>
		
		<summary type="html">&lt;p&gt;Benfellows: /* Policy Frameworks */ - two quick translations&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=[[Gu&amp;amp;iacute;a Portada|Portada]]=&lt;br /&gt;
#Dedicaci&amp;amp;oacute;n&lt;br /&gt;
#Derechos de autor y licencia&lt;br /&gt;
#Editores &lt;br /&gt;
#Autores y cr&amp;amp;iacute;ticos&lt;br /&gt;
#Historia de revisiones&lt;br /&gt;
=[[Acerca del Open Web Application Security Project]]=&lt;br /&gt;
#Estructura y licenciamiento&lt;br /&gt;
#Participaci&amp;amp;oacute;n y afiliaci&amp;amp;oacute;n&lt;br /&gt;
#Proyectos&lt;br /&gt;
&lt;br /&gt;
=[[Gu&amp;amp;iacute;a Introducci&amp;amp;oacute;n| Introducci&amp;amp;oacute;n]]=&lt;br /&gt;
#Desarrollando aplicaciones seguras&lt;br /&gt;
#Mejoras en esta edici&amp;amp;oacute;n&lt;br /&gt;
#Como usar la gu&amp;amp;iacute;a&lt;br /&gt;
#Actualizaciones y errata&lt;br /&gt;
#Agradecimientos&lt;br /&gt;
=[[¿Qué son las aplicaciones web?]]=&lt;br /&gt;
#Tecnologías&lt;br /&gt;
#La primera generación – CGI&lt;br /&gt;
#Filtros&lt;br /&gt;
#Scripting&lt;br /&gt;
#Web application frameworks – J&lt;br /&gt;
#Aplicaciones de pequeña y mediana escala&lt;br /&gt;
#Aplicaciones de gran escala&lt;br /&gt;
#Vista&lt;br /&gt;
#Controlador&lt;br /&gt;
#Modelo&lt;br /&gt;
#Conclusiones&lt;br /&gt;
&lt;br /&gt;
=[[Armazón de Reglas]]=&lt;br /&gt;
#Organizational commitment to security&lt;br /&gt;
#Lugar de OWASP al mesa de Armazónes&lt;br /&gt;
#Development Methodology&lt;br /&gt;
#Coding Standards&lt;br /&gt;
#Source Code Control&lt;br /&gt;
#Summary&lt;br /&gt;
&lt;br /&gt;
=[[Secure Coding Principles]]=&lt;br /&gt;
#Asset Classification&lt;br /&gt;
#About attackers&lt;br /&gt;
#Core pillars of information security&lt;br /&gt;
#Security Architecture&lt;br /&gt;
#Security Principles&lt;br /&gt;
=[[Threat Risk Modeling]]=&lt;br /&gt;
#Threat Risk Modeling&lt;br /&gt;
#Performing threat risk modeling using the Microsoft Threat Modeling Process&lt;br /&gt;
#Alternative Threat Modeling Systems&lt;br /&gt;
#Trike&lt;br /&gt;
#AS/NZS&lt;br /&gt;
#CVSS&lt;br /&gt;
#OCTAVE&lt;br /&gt;
#Conclusion&lt;br /&gt;
#Further Reading&lt;br /&gt;
=[[Handling E-Commerce Payments]]=&lt;br /&gt;
#Objectives&lt;br /&gt;
#Compliance and Laws&lt;br /&gt;
#PCI Compliance&lt;br /&gt;
#Handling Credit Cards&lt;br /&gt;
#Further Reading&lt;br /&gt;
=[[Phishing]]=&lt;br /&gt;
#What is phishing?&lt;br /&gt;
#User Education&lt;br /&gt;
#Make it easy for your users to report scams&lt;br /&gt;
#Communicating with customers via e-mail&lt;br /&gt;
#Never ask your customers for their secrets&lt;br /&gt;
#Fix all your XSS issues&lt;br /&gt;
#Do not use pop-ups&lt;br /&gt;
#Don’t be framed&lt;br /&gt;
#Move your application one link away from your front page&lt;br /&gt;
#Enforce local referrers for images and other resources&lt;br /&gt;
#Keep the address bar, use SSL, do not use IP addresses&lt;br /&gt;
#Don’t be the source of identity theft&lt;br /&gt;
#Implement safe-guards within your application&lt;br /&gt;
#Monitor unusual account activity&lt;br /&gt;
#Get the phishing target servers offline pronto&lt;br /&gt;
#Take control of the fraudulent domain name&lt;br /&gt;
#Work with law enforcement&lt;br /&gt;
#When an attack happens&lt;br /&gt;
#Further Reading&lt;br /&gt;
=[[Web Services]]=&lt;br /&gt;
#Securing Web Services&lt;br /&gt;
#Communication security&lt;br /&gt;
#Passing credentials&lt;br /&gt;
#Ensuring message freshness&lt;br /&gt;
#Protecting message integrity&lt;br /&gt;
#Protecting message confidentiality&lt;br /&gt;
#Access control&lt;br /&gt;
#Audit&lt;br /&gt;
#Web Services Security Hierarchy&lt;br /&gt;
#SOAP&lt;br /&gt;
#WS-Security Standard&lt;br /&gt;
#WS-Security Building Blocks&lt;br /&gt;
#Communication Protection Mechanisms&lt;br /&gt;
#Access Control Mechanisms&lt;br /&gt;
#Forming Web Service Chains&lt;br /&gt;
#Available Implementations&lt;br /&gt;
#Problems&lt;br /&gt;
#Further Reading&lt;br /&gt;
=[[Ajax and Other &amp;quot;Rich&amp;quot; Interface Technologies]]=&lt;br /&gt;
#Objective&lt;br /&gt;
#Platforms Affected&lt;br /&gt;
#Architecture&lt;br /&gt;
#Access control: Authentication and Authorization&lt;br /&gt;
#Silent transactional authorization&lt;br /&gt;
#Untrusted or absent session data&lt;br /&gt;
#State management&lt;br /&gt;
#Tamper resistance&lt;br /&gt;
#Privacy&lt;br /&gt;
#Proxy Façade&lt;br /&gt;
#SOAP Injection Attacks&lt;br /&gt;
#XMLRPC Injection Attacks&lt;br /&gt;
#DOM Injection Attacks&lt;br /&gt;
#XML Injection Attacks&lt;br /&gt;
#JSON (Javascript Object Notation) Injection Attacks&lt;br /&gt;
#Encoding safety&lt;br /&gt;
#Auditing&lt;br /&gt;
#Error Handling&lt;br /&gt;
#Accessibility&lt;br /&gt;
#Further Reading&lt;br /&gt;
=[[Autenticación]]=&lt;br /&gt;
#Objetivo&lt;br /&gt;
#Entornos afectados&lt;br /&gt;
#Relevant COBIT Topics&lt;br /&gt;
#Best Practices&lt;br /&gt;
#Técnicas comunes de autenticación web&lt;br /&gt;
#Autenticación fuerte&lt;br /&gt;
#Federated Authentication&lt;br /&gt;
#Controles de autenticación del lado del cliente&lt;br /&gt;
#Autenticación positiva&lt;br /&gt;
#Búsquedas en claves múltiples&lt;br /&gt;
#Verificaciión del Referer&lt;br /&gt;
#Guardando la clave en el navegador&lt;br /&gt;
#Cuentas por defecto&lt;br /&gt;
#Elección de nombres de usuario&lt;br /&gt;
#Cambiar las claves&lt;br /&gt;
#Claves cortas&lt;br /&gt;
#Controles de claves débiles &lt;br /&gt;
#Encriptación reversible de claves&lt;br /&gt;
#Automated password resets&lt;br /&gt;
#Fuerza Bruta&lt;br /&gt;
#Recordarme&lt;br /&gt;
#Idle Timeouts&lt;br /&gt;
#Logout&lt;br /&gt;
#Expiración de cuentas&lt;br /&gt;
#Autoregistro&lt;br /&gt;
#CAPTCHA&lt;br /&gt;
#Further Reading&lt;br /&gt;
#Authentication&lt;br /&gt;
&lt;br /&gt;
=[[Guide to Authorization]]=&lt;br /&gt;
#Objectives&lt;br /&gt;
#Environments Affected&lt;br /&gt;
#Relevant COBIT Topics&lt;br /&gt;
#Best Practices&lt;br /&gt;
#Best Practices in Action&lt;br /&gt;
#Principle of least privilege&lt;br /&gt;
#Centralized authorization routines&lt;br /&gt;
#Authorization matrix&lt;br /&gt;
#Controlling access to protected resources&lt;br /&gt;
#Protecting access to static resources&lt;br /&gt;
#Reauthorization for high value activities or after idle out&lt;br /&gt;
#Time based authorization&lt;br /&gt;
#Be cautious of custom authorization controls&lt;br /&gt;
#Never implement client-side authorization tokens&lt;br /&gt;
#Further Reading&lt;br /&gt;
&lt;br /&gt;
=[[Session Management]]=&lt;br /&gt;
#Objective&lt;br /&gt;
#Environments Affected&lt;br /&gt;
#Relevant COBIT Topics&lt;br /&gt;
#Description&lt;br /&gt;
#Best practices&lt;br /&gt;
#Exposed Session Variables&lt;br /&gt;
#Page and Form Tokens&lt;br /&gt;
#Weak Session Cryptographic Algorithms&lt;br /&gt;
#Session Token Entropy&lt;br /&gt;
#Session Time-out&lt;br /&gt;
#Regeneration of Session Tokens&lt;br /&gt;
#Session Forging/Brute-Forcing Detection and/or Lockout&lt;br /&gt;
#Session Token Capture and Session Hijacking&lt;br /&gt;
#Session Tokens on Logout&lt;br /&gt;
#Session Validation Attacks&lt;br /&gt;
#PHP&lt;br /&gt;
#Sessions&lt;br /&gt;
#Further Reading&lt;br /&gt;
#Session Management&lt;br /&gt;
=[[Data Validation]]=&lt;br /&gt;
#Objective&lt;br /&gt;
#Platforms Affected&lt;br /&gt;
#Relevant COBIT Topics&lt;br /&gt;
#Description&lt;br /&gt;
#Definitions&lt;br /&gt;
#Where to include integrity checks&lt;br /&gt;
#Where to include validation&lt;br /&gt;
#Where to include business rule validation&lt;br /&gt;
#Data Validation Strategies&lt;br /&gt;
#Prevent parameter tampering&lt;br /&gt;
#Hidden fields&lt;br /&gt;
#ASP.NET Viewstate&lt;br /&gt;
#URL encoding&lt;br /&gt;
#HTML encoding&lt;br /&gt;
#Encoded strings&lt;br /&gt;
#Data Validation and Interpreter Injection&lt;br /&gt;
#Delimiter and special characters&lt;br /&gt;
#Further Reading&lt;br /&gt;
=[[Interpreter Injection]]=&lt;br /&gt;
#Objective&lt;br /&gt;
#Platforms Affected&lt;br /&gt;
#Relevant COBIT Topics&lt;br /&gt;
#User Agent Injection&lt;br /&gt;
#HTTP Response Splitting&lt;br /&gt;
#SQL Injection&lt;br /&gt;
#ORM Injection&lt;br /&gt;
#LDAP Injection&lt;br /&gt;
#XML Injection&lt;br /&gt;
#Code Injection&lt;br /&gt;
#Further Reading&lt;br /&gt;
#SQL-injection&lt;br /&gt;
#Code Injection&lt;br /&gt;
#Command injection&lt;br /&gt;
=[[Canoncalization, locale and Unicode]]=&lt;br /&gt;
#Objective&lt;br /&gt;
#Platforms Affected&lt;br /&gt;
#Relevant COBIT Topics&lt;br /&gt;
#Description&lt;br /&gt;
#Unicode&lt;br /&gt;
#http://www.ietf.org/rfc/rfc#&lt;br /&gt;
#Input Formats&lt;br /&gt;
#Locale assertion&lt;br /&gt;
#Double (or n-) encoding&lt;br /&gt;
#	HTTP Request Smuggling&lt;br /&gt;
#	Further Reading&lt;br /&gt;
=[[Error Handling, Auditing and Logging]]=&lt;br /&gt;
#Objective&lt;br /&gt;
#Environments Affected&lt;br /&gt;
#Relevant COBIT Topics&lt;br /&gt;
#Description&lt;br /&gt;
#Best practices&lt;br /&gt;
#Error Handling&lt;br /&gt;
#Detailed error messages&lt;br /&gt;
#Logging&lt;br /&gt;
#Noise&lt;br /&gt;
#Cover Tracks&lt;br /&gt;
#False Alarms&lt;br /&gt;
#Destruction&lt;br /&gt;
#Audit Trails&lt;br /&gt;
#Further Reading&lt;br /&gt;
#Error Handling and Logging&lt;br /&gt;
=[[File System]]=&lt;br /&gt;
#Objective&lt;br /&gt;
#Environments Affected&lt;br /&gt;
#Relevant COBIT Topics&lt;br /&gt;
#Description&lt;br /&gt;
#Best Practices&lt;br /&gt;
#Defacement&lt;br /&gt;
#Path traversal&lt;br /&gt;
#Insecure permissions&lt;br /&gt;
#Insecure Indexing&lt;br /&gt;
#Unmapped files&lt;br /&gt;
#Temporary files&lt;br /&gt;
#PHP&lt;br /&gt;
#Includes and Remote files&lt;br /&gt;
#File upload&lt;br /&gt;
#Old, unreferenced files&lt;br /&gt;
#Second Order Injection&lt;br /&gt;
#Further Reading&lt;br /&gt;
#File System&lt;br /&gt;
=[[Distributed Computing]]=&lt;br /&gt;
#Objective&lt;br /&gt;
#Environments Affected&lt;br /&gt;
#Relevant COBIT Topics&lt;br /&gt;
#Best Practices&lt;br /&gt;
#Race conditions&lt;br /&gt;
#Distributed synchronization&lt;br /&gt;
#Further Reading&lt;br /&gt;
=[[Buffer Overflows]]=&lt;br /&gt;
#Objective&lt;br /&gt;
#Platforms Affected&lt;br /&gt;
#Relevant COBIT Topics&lt;br /&gt;
#Description&lt;br /&gt;
#General Prevention Techniques&lt;br /&gt;
#Stack Overflow&lt;br /&gt;
#Heap Overflow&lt;br /&gt;
#Format String&lt;br /&gt;
#Unicode Overflow&lt;br /&gt;
#Integer Overflow&lt;br /&gt;
#Further reading&lt;br /&gt;
=[[Administrative Interface]]=&lt;br /&gt;
#Objective&lt;br /&gt;
#Environments Affected&lt;br /&gt;
#Relevant COBIT Topics&lt;br /&gt;
#Best practices&lt;br /&gt;
#Administrators are not users&lt;br /&gt;
#Authentication for high value systems&lt;br /&gt;
#Further Reading&lt;br /&gt;
=[[Guide to Cryptography]]=&lt;br /&gt;
#Objective&lt;br /&gt;
#Platforms Affected&lt;br /&gt;
#Relevant COBIT Topics&lt;br /&gt;
#Description&lt;br /&gt;
#Cryptographic Functions&lt;br /&gt;
#Cryptographic Algorithms&lt;br /&gt;
#Algorithm Selection&lt;br /&gt;
#Key Storage&lt;br /&gt;
#Insecure transmission of secrets&lt;br /&gt;
#Reversible Authentication Tokens&lt;br /&gt;
#Safe UUID generation&lt;br /&gt;
#Summary&lt;br /&gt;
#Further Reading&lt;br /&gt;
#Cryptography&lt;br /&gt;
&lt;br /&gt;
=[[Configuration]]=&lt;br /&gt;
#Objective&lt;br /&gt;
#Platforms Affected&lt;br /&gt;
#Relevant COBIT Topics&lt;br /&gt;
#Best Practices&lt;br /&gt;
#Default passwords&lt;br /&gt;
#Secure connection strings&lt;br /&gt;
#Secure network transmission&lt;br /&gt;
#Encrypted data&lt;br /&gt;
#PHP Configuration&lt;br /&gt;
#Global variables&lt;br /&gt;
#register_globals&lt;br /&gt;
#Database security&lt;br /&gt;
#Further Reading&lt;br /&gt;
#ColdFusion Components (CFCs)&lt;br /&gt;
#Configuration&lt;br /&gt;
=[[Software Quality Assurance]]=&lt;br /&gt;
#Objective&lt;br /&gt;
#Platforms Affected&lt;br /&gt;
#Best practices&lt;br /&gt;
#Process&lt;br /&gt;
#Metrics&lt;br /&gt;
#Testing Activities&lt;br /&gt;
=[[Deployment]]=&lt;br /&gt;
#Objective&lt;br /&gt;
#Platforms Affected&lt;br /&gt;
#Best Practices&lt;br /&gt;
#Release Management&lt;br /&gt;
#Secure delivery of code&lt;br /&gt;
#Code signing&lt;br /&gt;
#Permissions are set to least privilege&lt;br /&gt;
#Automated packaging&lt;br /&gt;
#Automated deployment&lt;br /&gt;
#Automated removal&lt;br /&gt;
#No backup or old files&lt;br /&gt;
#Unnecessary features are off by default&lt;br /&gt;
#Setup log files are clean&lt;br /&gt;
#No default accounts&lt;br /&gt;
#Easter eggs&lt;br /&gt;
#Malicious software&lt;br /&gt;
#Further Reading&lt;br /&gt;
=[[Maintenance]]=&lt;br /&gt;
#Objective&lt;br /&gt;
#Platforms Affected&lt;br /&gt;
#Relevant COBIT Topics&lt;br /&gt;
#Best Practices&lt;br /&gt;
#Security Incident Response&lt;br /&gt;
#Fix Security Issues Correctly&lt;br /&gt;
#Update Notifications&lt;br /&gt;
#Regularly check permissions&lt;br /&gt;
#Further Reading&lt;br /&gt;
#Maintenance&lt;br /&gt;
=[[GNU Free Documentation License]]=&lt;br /&gt;
#PREAMBLE&lt;br /&gt;
#APPLICABILITY AND DEFINITIONS&lt;br /&gt;
#VERBATIM COPYING&lt;br /&gt;
#COPYING IN QUANTITY&lt;br /&gt;
#MODIFICATIONS&lt;br /&gt;
#COMBINING DOCUMENTS&lt;br /&gt;
#COLLECTIONS OF DOCUMENTS&lt;br /&gt;
#AGGREGATION WITH INDEPENDENT WORKS&lt;br /&gt;
#TRANSLATION&lt;br /&gt;
#TERMINATION&lt;br /&gt;
#FUTURE REVISIONS OF THIS LICENSE&lt;br /&gt;
=Reference=&lt;br /&gt;
[[Category:OWASP_Guide_Project]]&lt;/div&gt;</summary>
		<author><name>Benfellows</name></author>	</entry>

	</feed>