<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Dariodf</id>
		<title>OWASP - User contributions [en]</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Dariodf"/>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php/Special:Contributions/Dariodf"/>
		<updated>2026-04-23T23:23:53Z</updated>
		<subtitle>User contributions</subtitle>
		<generator>MediaWiki 1.27.2</generator>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cornucopia_-_Ecommerce_Website_Edition_-_Wiki_Deck&amp;diff=216979</id>
		<title>Cornucopia - Ecommerce Website Edition - Wiki Deck</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cornucopia_-_Ecommerce_Website_Edition_-_Wiki_Deck&amp;diff=216979"/>
				<updated>2016-05-17T19:44:41Z</updated>
		
		<summary type="html">&lt;p&gt;Dariodf: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__NOTOC__&lt;br /&gt;
Wiki Card Deck conceived and created by Darío De Filippis.&lt;br /&gt;
&lt;br /&gt;
= Versioning =&lt;br /&gt;
&lt;br /&gt;
This wiki deck relates to version 1.10 EN of [https://www.owasp.org/index.php/OWASP_Cornucopia OWASP Cornucopia] Ecommerce Website Edition (currently the only edition). The cards are available in other formats (DOC, PDF, print) from the main project pages.&lt;br /&gt;
&lt;br /&gt;
The cross-references relate to the following versions of other OWASP and external resources:&lt;br /&gt;
&lt;br /&gt;
* OWASP SCP [[OWASP_Secure_Coding_Practices_Checklist]] v2&lt;br /&gt;
* OWASP ASVS [[OWASP_Application_Security_Verification_Standard]] v2 (2014)&lt;br /&gt;
* OWASP AppSensor [[AppSensor_DetectionPoints]]&lt;br /&gt;
* CAPEC [https://capec.mitre.org Mitre Common Attack Pattern Enumeration and Classification] v1.7.1&lt;br /&gt;
* SAFECode [[SAFECode_Practical_Security_Stories|SAFECode Practical Security Stories and Security Tasks for Agile Development Environments]] July 2012&lt;br /&gt;
&lt;br /&gt;
= Deck =&lt;br /&gt;
&lt;br /&gt;
== &amp;lt;span style=&amp;quot;padding:5px;background:#929292;font-weight:bold;&amp;quot;&amp;gt; [[Cornucopia_-_Ecommerce_Website_-_VE|&amp;lt;span style=&amp;quot;color:white;&amp;quot;&amp;gt;Data validation and encoding (VE)&amp;lt;/span&amp;gt;]]&amp;lt;/span&amp;gt; ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;font-size:125%;letter-spacing: 0.15em;&amp;quot;&amp;gt;[[Cornucopia_-_Ecommerce_Website_-_VE_2|2]] [[Cornucopia_-_Ecommerce_Website_-_VE_3|3]] [[Cornucopia_-_Ecommerce_Website_-_VE_4|4]] [[Cornucopia_-_Ecommerce_Website_-_VE_5|5]] [[Cornucopia_-_Ecommerce_Website_-_VE_6|6]] [[Cornucopia_-_Ecommerce_Website_-_VE_7|7]] [[Cornucopia_-_Ecommerce_Website_-_VE_8|8]] [[Cornucopia_-_Ecommerce_Website_-_VE_9|9]] &amp;lt;span style=&amp;quot;letter-spacing: 0;&amp;quot;&amp;gt;[[Cornucopia_-_Ecommerce_Website_-_VE_10|10]]&amp;lt;/span&amp;gt; [[Cornucopia_-_Ecommerce_Website_-_VE_J|J]] [[Cornucopia_-_Ecommerce_Website_-_VE_Q|Q]] [[Cornucopia_-_Ecommerce_Website_-_VE_K|K]] [[Cornucopia_-_Ecommerce_Website_-_VE_A|A]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== &amp;lt;span style=&amp;quot;padding:5px;background:#73abcc;font-weight:bold;&amp;quot;&amp;gt; [[Cornucopia_-_Ecommerce_Website_-_AT|&amp;lt;span style=&amp;quot;color:white;&amp;quot;&amp;gt;Authentication (AT)&amp;lt;/span&amp;gt;]]&amp;lt;/span&amp;gt; ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;font-size:125%;letter-spacing: 0.15em;&amp;quot;&amp;gt;[[Cornucopia_-_Ecommerce_Website_-_AT_2|2]] [[Cornucopia_-_Ecommerce_Website_-_AT_3|3]] [[Cornucopia_-_Ecommerce_Website_-_AT_4|4]] [[Cornucopia_-_Ecommerce_Website_-_AT_5|5]] [[Cornucopia_-_Ecommerce_Website_-_AT_6|6]] [[Cornucopia_-_Ecommerce_Website_-_AT_7|7]] [[Cornucopia_-_Ecommerce_Website_-_AT_8|8]] [[Cornucopia_-_Ecommerce_Website_-_AT_9|9]] &amp;lt;span style=&amp;quot;letter-spacing: 0;&amp;quot;&amp;gt;[[Cornucopia_-_Ecommerce_Website_-_AT_10|10]]&amp;lt;/span&amp;gt; [[Cornucopia_-_Ecommerce_Website_-_AT_J|J]] [[Cornucopia_-_Ecommerce_Website_-_AT_Q|Q]] [[Cornucopia_-_Ecommerce_Website_-_AT_K|K]] [[Cornucopia_-_Ecommerce_Website_-_AT_A|A]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== &amp;lt;span style=&amp;quot;padding:5px;background:#98c477;font-weight:bold;&amp;quot;&amp;gt; [[Cornucopia_-_Ecommerce_Website_-_SM|&amp;lt;span style=&amp;quot;color:white;&amp;quot;&amp;gt;Session management (SM)&amp;lt;/span&amp;gt;]]&amp;lt;/span&amp;gt; ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;font-size:125%;letter-spacing: 0.15em;&amp;quot;&amp;gt;[[Cornucopia_-_Ecommerce_Website_-_SM_2|2]] [[Cornucopia_-_Ecommerce_Website_-_SM_3|3]] [[Cornucopia_-_Ecommerce_Website_-_SM_4|4]] [[Cornucopia_-_Ecommerce_Website_-_SM_5|5]] [[Cornucopia_-_Ecommerce_Website_-_SM_6|6]] [[Cornucopia_-_Ecommerce_Website_-_SM_7|7]] [[Cornucopia_-_Ecommerce_Website_-_SM_8|8]] [[Cornucopia_-_Ecommerce_Website_-_SM_9|9]] &amp;lt;span style=&amp;quot;letter-spacing: 0;&amp;quot;&amp;gt;[[Cornucopia_-_Ecommerce_Website_-_SM_10|10]]&amp;lt;/span&amp;gt; [[Cornucopia_-_Ecommerce_Website_-_SM_J|J]] [[Cornucopia_-_Ecommerce_Website_-_SM_Q|Q]] [[Cornucopia_-_Ecommerce_Website_-_SM_K|K]] [[Cornucopia_-_Ecommerce_Website_-_SM_A|A]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== &amp;lt;span style=&amp;quot;padding:5px;background:#d9c049;font-weight:bold;&amp;quot;&amp;gt; [[Cornucopia_-_Ecommerce_Website_-_AZ|&amp;lt;span style=&amp;quot;color:white;&amp;quot;&amp;gt;Authorization (AZ)&amp;lt;/span&amp;gt;]]&amp;lt;/span&amp;gt; ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;font-size:125%;letter-spacing: 0.15em;&amp;quot;&amp;gt;[[Cornucopia_-_Ecommerce_Website_-_AZ_2|2]] [[Cornucopia_-_Ecommerce_Website_-_AZ_3|3]] [[Cornucopia_-_Ecommerce_Website_-_AZ_4|4]] [[Cornucopia_-_Ecommerce_Website_-_AZ_5|5]] [[Cornucopia_-_Ecommerce_Website_-_AZ_6|6]] [[Cornucopia_-_Ecommerce_Website_-_AZ_7|7]] [[Cornucopia_-_Ecommerce_Website_-_AZ_8|8]] [[Cornucopia_-_Ecommerce_Website_-_AZ_9|9]] &amp;lt;span style=&amp;quot;letter-spacing: 0;&amp;quot;&amp;gt;[[Cornucopia_-_Ecommerce_Website_-_AZ_10|10]]&amp;lt;/span&amp;gt; [[Cornucopia_-_Ecommerce_Website_-_AZ_J|J]] [[Cornucopia_-_Ecommerce_Website_-_AZ_Q|Q]] [[Cornucopia_-_Ecommerce_Website_-_AZ_K|K]] [[Cornucopia_-_Ecommerce_Website_-_AZ_A|A]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== &amp;lt;span style=&amp;quot;padding:5px;background:#a395ca;font-weight:bold;&amp;quot;&amp;gt; [[Cornucopia_-_Ecommerce_Website_-_CR|&amp;lt;span style=&amp;quot;color:white;&amp;quot;&amp;gt;Cryptography (CR)&amp;lt;/span&amp;gt;]]&amp;lt;/span&amp;gt; ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;font-size:125%;letter-spacing: 0.15em;&amp;quot;&amp;gt;[[Cornucopia_-_Ecommerce_Website_-_CR_2|2]] [[Cornucopia_-_Ecommerce_Website_-_CR_3|3]] [[Cornucopia_-_Ecommerce_Website_-_CR_4|4]] [[Cornucopia_-_Ecommerce_Website_-_CR_5|5]] [[Cornucopia_-_Ecommerce_Website_-_CR_6|6]] [[Cornucopia_-_Ecommerce_Website_-_CR_7|7]] [[Cornucopia_-_Ecommerce_Website_-_CR_8|8]] [[Cornucopia_-_Ecommerce_Website_-_CR_9|9]] &amp;lt;span style=&amp;quot;letter-spacing: 0;&amp;quot;&amp;gt;[[Cornucopia_-_Ecommerce_Website_-_CR_10|10]]&amp;lt;/span&amp;gt; [[Cornucopia_-_Ecommerce_Website_-_CR_J|J]] [[Cornucopia_-_Ecommerce_Website_-_CR_Q|Q]] [[Cornucopia_-_Ecommerce_Website_-_CR_K|K]] [[Cornucopia_-_Ecommerce_Website_-_CR_A|A]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== &amp;lt;span style=&amp;quot;padding:5px;background:#17365d;font-weight:bold;&amp;quot;&amp;gt; [[Cornucopia_-_Ecommerce_Website_-_C|&amp;lt;span style=&amp;quot;color:white;&amp;quot;&amp;gt;Cornucopia (C)&amp;lt;/span&amp;gt;]]&amp;lt;/span&amp;gt; ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;font-size:125%;letter-spacing: 0.15em;&amp;quot;&amp;gt;[[Cornucopia_-_Ecommerce_Website_-_C_2|2]] [[Cornucopia_-_Ecommerce_Website_-_C_3|3]] [[Cornucopia_-_Ecommerce_Website_-_C_4|4]] [[Cornucopia_-_Ecommerce_Website_-_C_5|5]] [[Cornucopia_-_Ecommerce_Website_-_C_6|6]] [[Cornucopia_-_Ecommerce_Website_-_C_7|7]] [[Cornucopia_-_Ecommerce_Website_-_C_8|8]] [[Cornucopia_-_Ecommerce_Website_-_C_9|9]] &amp;lt;span style=&amp;quot;letter-spacing: 0;&amp;quot;&amp;gt;[[Cornucopia_-_Ecommerce_Website_-_C_10|10]]&amp;lt;/span&amp;gt; [[Cornucopia_-_Ecommerce_Website_-_C_J|J]] [[Cornucopia_-_Ecommerce_Website_-_C_Q|Q]] [[Cornucopia_-_Ecommerce_Website_-_C_K|K]] [[Cornucopia_-_Ecommerce_Website_-_C_A|A]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== &amp;lt;span style=&amp;quot;padding:5px;background:#fbbb7b;font-weight:bold;&amp;quot;&amp;gt; [[Cornucopia_-_Ecommerce_Website_-_W|&amp;lt;span style=&amp;quot;color:white;&amp;quot;&amp;gt;Wild Card (W)&amp;lt;/span&amp;gt;]]&amp;lt;/span&amp;gt; ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;font-size:125%;&amp;quot;&amp;gt;[[Cornucopia_-_Ecommerce_Website_-_W_Joker_A|Joker (A)]]&amp;lt;span style=&amp;quot;letter-spacing: 0.15em;&amp;quot;&amp;gt; &amp;lt;/span&amp;gt;[[Cornucopia_-_Ecommerce_Website_-_W_Joker_B|Joker (B)]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category: Attack]] [[Category: Threat_Modeling]]  [[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]] [[Category:OWASP_Document]] [[Category:SAMM-SR-1]] [[Category:SAMM-SR-2]] [[Category:SAMM-TA-1]] [[Category:SAMM-EG-2]]&lt;/div&gt;</summary>
		<author><name>Dariodf</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cornucopia_-_Ecommerce_Website_-_CR_5&amp;diff=212070</id>
		<title>Cornucopia - Ecommerce Website - CR 5</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cornucopia_-_Ecommerce_Website_-_CR_5&amp;diff=212070"/>
				<updated>2016-03-29T20:37:57Z</updated>
		
		<summary type="html">&lt;p&gt;Dariodf: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{DISPLAYTITLE:&amp;lt;span style=&amp;quot;padding:2px 5px 0px 5px;color:white;background:#a395ca;&amp;quot;&amp;gt;Cornucopia - Ecommerce Website - CR 5&amp;lt;/span&amp;gt;}}&lt;br /&gt;
[[File:Cornucopia_-_Ecommerce_Website_CR_5.png|frame|right]]&lt;br /&gt;
'''Suit:''' [[Cornucopia_-_Ecommerce_Website_-_CR|Cryptography]]&lt;br /&gt;
&lt;br /&gt;
'''Card/Value:''' 5&lt;br /&gt;
&lt;br /&gt;
=== Description: ===&lt;br /&gt;
&lt;br /&gt;
Kyle can bypass cryptographic controls because they do not fail securely (i.e. they default to unprotected).&lt;br /&gt;
&lt;br /&gt;
=== Technical Note: ===&lt;br /&gt;
&lt;br /&gt;
Cryptographic function errors always need to result in rejection. It is also useful to log (associated with the user's identity if possible) and flag these as possibly malicious activity for further analysis, or as input for application intrusion detection systems.&lt;br /&gt;
&lt;br /&gt;
NB: Unlike [[Cornucopia_-_Ecommerce_Website_-_CR|other cards in this suit]], CR 5 assumes that cryptographic functions are in place, however they do not correctly respond to errors.&lt;br /&gt;
&lt;br /&gt;
=== References: ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;table class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center;&amp;quot;&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;OWASP SCP&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;OWASP ASVS&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;OWASP AppSensor&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;CAPEC&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;SAFECODE&amp;lt;/th&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#103|103]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Application_Security_Verification_Standard#7.2|7.2]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[https://capec.mitre.org/data/definitions/97.html 97]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[SAFECode_Practical_Security_Stories#21|21]]&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#145|145]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[SAFECode_Practical_Security_Stories#29|29]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;padding:5px;background:LightGray;color:White;font-weight:bold;&amp;quot;&amp;gt;[[Cornucopia_-_Ecommerce_Website_-_CR_4|« Previous Card]] &amp;lt;span style=&amp;quot;padding-left:10px;padding-right:10px;&amp;quot;&amp;gt;|&amp;lt;/span&amp;gt;  [[Cornucopia_-_Ecommerce_Website_-_CR|Cryptography]] &amp;lt;span style=&amp;quot;padding-left:10px;padding-right:10px;&amp;quot;&amp;gt;|&amp;lt;/span&amp;gt; [[Cornucopia_-_Ecommerce_Website_-_CR_6|Next Card »]] &amp;lt;/div&amp;gt;&lt;/div&gt;</summary>
		<author><name>Dariodf</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cornucopia_-_Ecommerce_Website_-_CR_2&amp;diff=212069</id>
		<title>Cornucopia - Ecommerce Website - CR 2</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cornucopia_-_Ecommerce_Website_-_CR_2&amp;diff=212069"/>
				<updated>2016-03-29T20:37:38Z</updated>
		
		<summary type="html">&lt;p&gt;Dariodf: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{DISPLAYTITLE:&amp;lt;span style=&amp;quot;padding:2px 5px 0px 5px;color:white;background:#a395ca;&amp;quot;&amp;gt;Cornucopia - Ecommerce Website - CR 2&amp;lt;/span&amp;gt;}}&lt;br /&gt;
[[File:Cornucopia_-_Ecommerce_Website_CR_2.png|frame|right]]&lt;br /&gt;
'''Suit:''' [[Cornucopia_-_Ecommerce_Website_-_CR|Cryptography]]&lt;br /&gt;
&lt;br /&gt;
'''Card/Value:''' 2&lt;br /&gt;
&lt;br /&gt;
=== Description: ===&lt;br /&gt;
&lt;br /&gt;
Kyun can access data because it has been obfuscated rather than using an approved cryptographic function.&lt;br /&gt;
&lt;br /&gt;
=== Technical Note: ===&lt;br /&gt;
&lt;br /&gt;
There is no substitute for a proper, approved, cryptographic function where data needs to be protected at rest or in transit. Obfuscation is rarely the correct choice. Use standard-approved functions and consider all cryptographic management requirements (e.g. key creation, distribution, protection, replacement, retirement).&lt;br /&gt;
&lt;br /&gt;
=== References: ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;table class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center;&amp;quot;&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;OWASP SCP&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;OWASP ASVS&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;OWASP AppSensor&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;CAPEC&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;SAFECODE&amp;lt;/th&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#105|105]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[SAFECode_Practical_Security_Stories#21|21]]&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#133|133]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[SAFECode_Practical_Security_Stories#29|29]]&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#135|135]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;padding:5px;background:LightGray;color:White;font-weight:bold;&amp;quot;&amp;gt;[[Cornucopia_-_Ecommerce_Website_-_AZ_A|« Previous Card]] &amp;lt;span style=&amp;quot;padding-left:10px;padding-right:10px;&amp;quot;&amp;gt;|&amp;lt;/span&amp;gt;  [[Cornucopia_-_Ecommerce_Website_-_CR|Cryptography]] &amp;lt;span style=&amp;quot;padding-left:10px;padding-right:10px;&amp;quot;&amp;gt;|&amp;lt;/span&amp;gt; [[Cornucopia_-_Ecommerce_Website_-_CR_3|Next Card »]] &amp;lt;/div&amp;gt;&lt;/div&gt;</summary>
		<author><name>Dariodf</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cornucopia_-_Ecommerce_Website_-_AZ_10&amp;diff=212067</id>
		<title>Cornucopia - Ecommerce Website - AZ 10</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cornucopia_-_Ecommerce_Website_-_AZ_10&amp;diff=212067"/>
				<updated>2016-03-29T20:32:47Z</updated>
		
		<summary type="html">&lt;p&gt;Dariodf: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{DISPLAYTITLE:&amp;lt;span style=&amp;quot;padding:2px 5px 0px 5px;color:white;background:#d9c049;&amp;quot;&amp;gt;Cornucopia - Ecommerce Website - AZ 10&amp;lt;/span&amp;gt;}}&lt;br /&gt;
[[File:Cornucopia_-_Ecommerce_Website_AZ_10.png|frame|right]]&lt;br /&gt;
'''Suit:''' [[Cornucopia_-_Ecommerce_Website_-_AZ|Authorization]]&lt;br /&gt;
&lt;br /&gt;
'''Card/Value:''' 10&lt;br /&gt;
&lt;br /&gt;
=== Description: ===&lt;br /&gt;
&lt;br /&gt;
Richard can bypass the centralized authorization controls since they are not being used comprehensively on all interactions.&lt;br /&gt;
&lt;br /&gt;
=== Technical Note: ===&lt;br /&gt;
&lt;br /&gt;
Centralized authorization routines are a good programming practice, but like other routines, developers need to understand how they work, how to use them and any limitations. Such routines can be tested independently of other code and not only provide assurance on the quality, but also make refactorization an easy task and eliminate code duplicates and bad interpretations.&lt;br /&gt;
&lt;br /&gt;
Server side implementation and presentation layer representations of access control rules must match.&lt;br /&gt;
&lt;br /&gt;
=== References: ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;table class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center;&amp;quot;&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;OWASP SCP&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;OWASP ASVS&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;OWASP AppSensor&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;CAPEC&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;SAFECODE&amp;lt;/th&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#78|78]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Application_Security_Verification_Standard#4.1|4.1]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[AppSensor_DetectionPoints#ACE1|ACE1]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[https://capec.mitre.org/data/definitions/36.html 36]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[SAFECode_Practical_Security_Stories#8|8]]&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#91|91]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Application_Security_Verification_Standard#4.12|4.12]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[AppSensor_DetectionPoints#ACE2|ACE2]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[https://capec.mitre.org/data/definitions/95.html 95]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[SAFECode_Practical_Security_Stories#10|10]]&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[AppSensor_DetectionPoints#ACE3|ACE3]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[https://capec.mitre.org/data/definitions/121.html 121]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[SAFECode_Practical_Security_Stories#11|11]]&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[AppSensor_DetectionPoints#ACE4|ACE4]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[https://capec.mitre.org/data/definitions/179.html 179]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;padding:5px;background:LightGray;color:White;font-weight:bold;&amp;quot;&amp;gt;[[Cornucopia_-_Ecommerce_Website_-_AZ_9|« Previous Card]] &amp;lt;span style=&amp;quot;padding-left:10px;padding-right:10px;&amp;quot;&amp;gt;|&amp;lt;/span&amp;gt;  [[Cornucopia_-_Ecommerce_Website_-_AZ|Authorization]] &amp;lt;span style=&amp;quot;padding-left:10px;padding-right:10px;&amp;quot;&amp;gt;|&amp;lt;/span&amp;gt; [[Cornucopia_-_Ecommerce_Website_-_AZ_J|Next Card »]] &amp;lt;/div&amp;gt;&lt;/div&gt;</summary>
		<author><name>Dariodf</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cornucopia_-_Ecommerce_Website_-_AZ_4&amp;diff=212065</id>
		<title>Cornucopia - Ecommerce Website - AZ 4</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cornucopia_-_Ecommerce_Website_-_AZ_4&amp;diff=212065"/>
				<updated>2016-03-29T20:21:20Z</updated>
		
		<summary type="html">&lt;p&gt;Dariodf: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{DISPLAYTITLE:&amp;lt;span style=&amp;quot;padding:2px 5px 0px 5px;color:white;background:#d9c049;&amp;quot;&amp;gt;Cornucopia - Ecommerce Website - AZ 4&amp;lt;/span&amp;gt;}}&lt;br /&gt;
[[File:Cornucopia_-_Ecommerce_Website_AZ_4.png|frame|right]]&lt;br /&gt;
'''Suit:''' [[Cornucopia_-_Ecommerce_Website_-_AZ|Authorization]]&lt;br /&gt;
&lt;br /&gt;
'''Card/Value:''' 4&lt;br /&gt;
&lt;br /&gt;
=== Description: ===&lt;br /&gt;
&lt;br /&gt;
Kelly can bypass authorization controls because they do not fail securely (i.e. they default to allowing access).&lt;br /&gt;
&lt;br /&gt;
=== Technical Note: ===&lt;br /&gt;
&lt;br /&gt;
Once an authorization failure is detected, access needs to be blocked.  It is also useful to log (associated with the user's identity if possible) and flag these as possibly malicious activity for further analysis, or as input for application intrusion detection systems.&lt;br /&gt;
&lt;br /&gt;
NB: the key concept for this card is allowing access, even though authorization checks were undertaken and detected a failure. See [[Cornucopia_-_Ecommerce_Website_-_AT_8|AT 8]] for the similar authentication failure.&lt;br /&gt;
&lt;br /&gt;
=== References: ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;table class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center;&amp;quot;&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;OWASP SCP&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;OWASP ASVS&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;OWASP AppSensor&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;CAPEC&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;SAFECODE&amp;lt;/th&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#79|79]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Application_Security_Verification_Standard#4.8|4.8]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[https://capec.mitre.org/data/definitions/122.html 122]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[SAFECode_Practical_Security_Stories#8|8]]&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#80|80]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[SAFECode_Practical_Security_Stories#10|10]]&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[SAFECode_Practical_Security_Stories#11|11]]&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;padding:5px;background:LightGray;color:White;font-weight:bold;&amp;quot;&amp;gt;[[Cornucopia_-_Ecommerce_Website_-_AZ_3|« Previous Card]] &amp;lt;span style=&amp;quot;padding-left:10px;padding-right:10px;&amp;quot;&amp;gt;|&amp;lt;/span&amp;gt;  [[Cornucopia_-_Ecommerce_Website_-_AZ|Authorization]] &amp;lt;span style=&amp;quot;padding-left:10px;padding-right:10px;&amp;quot;&amp;gt;|&amp;lt;/span&amp;gt; [[Cornucopia_-_Ecommerce_Website_-_AZ_5|Next Card »]] &amp;lt;/div&amp;gt;&lt;/div&gt;</summary>
		<author><name>Dariodf</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cornucopia_-_Ecommerce_Website_-_AZ_3&amp;diff=212064</id>
		<title>Cornucopia - Ecommerce Website - AZ 3</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cornucopia_-_Ecommerce_Website_-_AZ_3&amp;diff=212064"/>
				<updated>2016-03-29T20:18:35Z</updated>
		
		<summary type="html">&lt;p&gt;Dariodf: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{DISPLAYTITLE:&amp;lt;span style=&amp;quot;padding:2px 5px 0px 5px;color:white;background:#d9c049;&amp;quot;&amp;gt;Cornucopia - Ecommerce Website - AZ 3&amp;lt;/span&amp;gt;}}&lt;br /&gt;
[[File:Cornucopia_-_Ecommerce_Website_AZ_3.png|frame|right]]&lt;br /&gt;
'''Suit:''' [[Cornucopia_-_Ecommerce_Website_-_AZ|Authorization]]&lt;br /&gt;
&lt;br /&gt;
'''Card/Value:''' 3&lt;br /&gt;
&lt;br /&gt;
=== Description: ===&lt;br /&gt;
&lt;br /&gt;
Christian can access information, which they should not have permission to, through another mechanism that does have permission (e.g. search indexer, logger, reporting), or because it is cached, or kept for longer than necessary, or other information leakage.&lt;br /&gt;
&lt;br /&gt;
=== Technical Note: ===&lt;br /&gt;
&lt;br /&gt;
The attacker themselves is not permitted direct access, but has access to something, that had or has access to information. Consider all accounts/roles and what access privileges they have, and whether a user in one role can utilise another role. Create an Access Control Policy to document an application's business rules, data types and access authorization criteria and/or processes so that access can be properly provisioned and controlled. This includes identifying access requirements for both the data and system resources.&lt;br /&gt;
&lt;br /&gt;
This card also includes considerations of access to residual information such as cached data, data stored temporarily, and the inadequate deletion of information that is no longer required (and has passed its required retention period).&lt;br /&gt;
&lt;br /&gt;
=== References: ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;table class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center;&amp;quot;&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;OWASP SCP&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;OWASP ASVS&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;OWASP AppSensor&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;CAPEC&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;SAFECODE&amp;lt;/th&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#51|51]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Application_Security_Verification_Standard#4.1|4.1]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[https://capec.mitre.org/data/definitions/69.html 69]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[SAFECode_Practical_Security_Stories#8|8]]&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#100|100]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Application_Security_Verification_Standard#8.10|8.10]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[https://capec.mitre.org/data/definitions/213.html 213]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[SAFECode_Practical_Security_Stories#10|10]]&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#135|135]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Application_Security_Verification_Standard#9.1|9.1]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[SAFECode_Practical_Security_Stories#11|11]]&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#139|139]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Application_Security_Verification_Standard#9.2|9.2]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#140|140]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Application_Security_Verification_Standard#9.3|9.3]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#141|141]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Application_Security_Verification_Standard#9.4|9.4]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#150|150]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Application_Security_Verification_Standard#9.5|9.5]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Application_Security_Verification_Standard#9.6|9.6]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Application_Security_Verification_Standard#17.18|17.18]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;padding:5px;background:LightGray;color:White;font-weight:bold;&amp;quot;&amp;gt;[[Cornucopia_-_Ecommerce_Website_-_AZ_2|« Previous Card]] &amp;lt;span style=&amp;quot;padding-left:10px;padding-right:10px;&amp;quot;&amp;gt;|&amp;lt;/span&amp;gt;  [[Cornucopia_-_Ecommerce_Website_-_AZ|Authorization]] &amp;lt;span style=&amp;quot;padding-left:10px;padding-right:10px;&amp;quot;&amp;gt;|&amp;lt;/span&amp;gt; [[Cornucopia_-_Ecommerce_Website_-_AZ_4|Next Card »]] &amp;lt;/div&amp;gt;&lt;/div&gt;</summary>
		<author><name>Dariodf</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cornucopia_-_Ecommerce_Website_-_VE_10&amp;diff=212063</id>
		<title>Cornucopia - Ecommerce Website - VE 10</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cornucopia_-_Ecommerce_Website_-_VE_10&amp;diff=212063"/>
				<updated>2016-03-29T20:07:08Z</updated>
		
		<summary type="html">&lt;p&gt;Dariodf: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{DISPLAYTITLE:&amp;lt;span style=&amp;quot;padding:2px 5px 0px 5px;color:white;background:#929292;&amp;quot;&amp;gt;Cornucopia - Ecommerce Website - VE 10&amp;lt;/span&amp;gt;}}&lt;br /&gt;
[[File:Cornucopia_-_Ecommerce_Website_VE_10.png|frame|right]]&lt;br /&gt;
'''Suit:''' [[Cornucopia_-_Ecommerce_Website_-_VE|Data Validation and Encoding]]&lt;br /&gt;
&lt;br /&gt;
'''Card/Value:''' 10&lt;br /&gt;
&lt;br /&gt;
=== Description: ===&lt;br /&gt;
&lt;br /&gt;
Jerry can exploit the trust the application places in a source of data (e.g. user-definable data, manipulation of locally stored data, alteration to state data on a client device, lack of verification of identity during data validation such as Jerry can pretend to be Colin).&lt;br /&gt;
&lt;br /&gt;
=== Technical Note: ===&lt;br /&gt;
&lt;br /&gt;
Trust management is a popular technique for implementing information security, and specifically for access control policies. All data sources of an application are be classified into groups with varying degrees of trust. When doing this, it is imperative to ensure that trusted sources cannot be spoofed. This spoofing can be done in many ways:&lt;br /&gt;
* Reflection attack.&lt;br /&gt;
* Principal Spoof.&lt;br /&gt;
* JSON Hijacking.&lt;br /&gt;
* Registry Poisoning.&lt;br /&gt;
* MITM.&lt;br /&gt;
* XSS.&lt;br /&gt;
Attackers that are identified as trusted users or that are in a trusted zone with bad authentication techniques can do all sorts of things, depending on the services, such as:&lt;br /&gt;
* Sniffing.&lt;br /&gt;
* Data tampering.&lt;br /&gt;
* Code Injection.&lt;br /&gt;
* DoS.&lt;br /&gt;
&lt;br /&gt;
=== References: ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;table class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center;&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;th&amp;gt;OWASP SCP &amp;lt;/th&amp;gt;&lt;br /&gt;
&amp;lt;th&amp;gt;OWASP ASVS &amp;lt;/th&amp;gt;&lt;br /&gt;
&amp;lt;th&amp;gt;OWASP AppSensor &amp;lt;/th&amp;gt;&lt;br /&gt;
&amp;lt;th&amp;gt;CAPEC &amp;lt;/th&amp;gt;&lt;br /&gt;
&amp;lt;th&amp;gt;SAFECODE &amp;lt;/th&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#2|2]]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[[OWASP_Application_Security_Verification_Standard#10.6|10.6]]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[[AppSensor_DetectionPoints#IE4|IE4]]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[https://capec.mitre.org/data/definitions/12.html 12]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[[SAFECode_Practical_Security_Stories#14|14]]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#19|19]]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt; &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[[AppSensor_DetectionPoints#IE5|IE5]]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[https://capec.mitre.org/data/definitions/51.html 51]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt; &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#92|92]]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt; &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt; &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[https://capec.mitre.org/data/definitions/57.html 57]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt; &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#95|95]]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt; &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt; &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[https://capec.mitre.org/data/definitions/90.html 90]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt; &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#180|180]]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt; &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt; &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[https://capec.mitre.org/data/definitions/111.html 111]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt; &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt; &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt; &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt; &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[https://capec.mitre.org/data/definitions/145.html 145]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt; &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt; &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt; &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt; &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[https://capec.mitre.org/data/definitions/194.html 194]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt; &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt; &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt; &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt; &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[https://capec.mitre.org/data/definitions/195.html 195]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt; &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt; &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt; &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt; &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[https://capec.mitre.org/data/definitions/202.html 202]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt; &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt; &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt; &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt; &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[https://capec.mitre.org/data/definitions/218.html 218]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt; &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt; &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt; &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt; &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[https://capec.mitre.org/data/definitions/463.html 463]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;padding:5px;background:LightGray;color:White;font-weight:bold;&amp;quot;&amp;gt;[[Cornucopia_-_Ecommerce_Website_-_VE_9|« Previous Card]] &amp;lt;span style=&amp;quot;padding-left:10px;padding-right:10px;&amp;quot;&amp;gt;|&amp;lt;/span&amp;gt;  [[Cornucopia_-_Ecommerce_Website_-_VE|Data Validation and Encoding]] &amp;lt;span style=&amp;quot;padding-left:10px;padding-right:10px;&amp;quot;&amp;gt;|&amp;lt;/span&amp;gt; [[Cornucopia_-_Ecommerce_Website_-_VE_J|Next Card »]] &amp;lt;/div&amp;gt;&lt;/div&gt;</summary>
		<author><name>Dariodf</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cornucopia_-_Ecommerce_Website_-_VE_4&amp;diff=212062</id>
		<title>Cornucopia - Ecommerce Website - VE 4</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cornucopia_-_Ecommerce_Website_-_VE_4&amp;diff=212062"/>
				<updated>2016-03-29T20:02:13Z</updated>
		
		<summary type="html">&lt;p&gt;Dariodf: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{DISPLAYTITLE:&amp;lt;span style=&amp;quot;padding:2px 5px 0px 5px;color:white;background:#929292;&amp;quot;&amp;gt;Cornucopia - Ecommerce Website - VE 4&amp;lt;/span&amp;gt;}}&lt;br /&gt;
[[File:Cornucopia_-_Ecommerce_Website_VE_4.png|frame|right]]&lt;br /&gt;
'''Suit:''' [[Cornucopia_-_Ecommerce_Website_-_VE|Data Validation and Encoding]]&lt;br /&gt;
&lt;br /&gt;
'''Card/Value:''' 4&lt;br /&gt;
&lt;br /&gt;
=== Description: ===&lt;br /&gt;
&lt;br /&gt;
Dave can input malicious field names or data because it is not being checked within the context of the current user and process.&lt;br /&gt;
&lt;br /&gt;
=== Technical Note: ===&lt;br /&gt;
&lt;br /&gt;
Malicious data can be introduced voluntarily (as part of an attack) or involuntarily (e.g. XSS). Some input checks should be dependent upon the function or user's context (e.g. the data is valid for one user but not another). There are many alternatives to this kind of attack:&lt;br /&gt;
* Tampering request types, URLs, cookies, session identifiers, fields or values that are not validated.&lt;br /&gt;
* Adding, removing or duplicating request fields or values to exploit code behaviour (e.g. mass parameter assignment, parameter pollution, passing partial authentication data).&lt;br /&gt;
* Sending requests that are processed independently of the user activities (stage, amount of requests, privileges).&lt;br /&gt;
* Fuzzing a file input.&lt;br /&gt;
Depending of the target of the attack, the results of this type of input varies widely:&lt;br /&gt;
* Information disclosure (error logs, system responses, etc.). &lt;br /&gt;
* Operations tampering (SQLi, eShoplifting).&lt;br /&gt;
* Denial of Service.&lt;br /&gt;
* Spoofing.&lt;br /&gt;
* Code execution.&lt;br /&gt;
&lt;br /&gt;
NB: This card relates to '''context-specific input validation'''. See [[Cornucopia_-_Ecommerce_Website_-_VE_3|VE 3]] for the similar generic input validation checks.&lt;br /&gt;
&lt;br /&gt;
=== References: ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;table class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center;&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;th&amp;gt;OWASP SCP &amp;lt;/th&amp;gt;&lt;br /&gt;
&amp;lt;th&amp;gt;OWASP ASVS &amp;lt;/th&amp;gt;&lt;br /&gt;
&amp;lt;th&amp;gt;OWASP AppSensor &amp;lt;/th&amp;gt;&lt;br /&gt;
&amp;lt;th&amp;gt;CAPEC &amp;lt;/th&amp;gt;&lt;br /&gt;
&amp;lt;th&amp;gt;SAFECODE &amp;lt;/th&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#8|8]]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[[OWASP_Application_Security_Verification_Standard#5.17|5.17]]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[[AppSensor_DetectionPoints#RE3|RE3]]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[https://capec.mitre.org/data/definitions/28.html 28]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[[SAFECode_Practical_Security_Stories#24|24]]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#10|10]]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[[OWASP_Application_Security_Verification_Standard#15.2|15.2]]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[[AppSensor_DetectionPoints#RE4|RE4]]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[https://capec.mitre.org/data/definitions/31.html 31]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[[SAFECode_Practical_Security_Stories#35|35]]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#183|183]]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[[OWASP_Application_Security_Verification_Standard#15.3|15.3]]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[[AppSensor_DetectionPoints#RE5|RE5]]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[https://capec.mitre.org/data/definitions/48.html 48]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt; &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt; &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[[OWASP_Application_Security_Verification_Standard#15.10|15.10]]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[[AppSensor_DetectionPoints#RE6|RE6]]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[https://capec.mitre.org/data/definitions/126.html 126]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt; &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt; &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt; &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[[AppSensor_DetectionPoints#AE8|AE8]]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[https://capec.mitre.org/data/definitions/162.html 162]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt; &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt; &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt; &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[[AppSensor_DetectionPoints#AE9|AE9]]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[https://capec.mitre.org/data/definitions/165.html 165]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt; &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt; &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt; &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[[AppSensor_DetectionPoints#AE10|AE10]]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[https://capec.mitre.org/data/definitions/213.html 213]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt; &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt; &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt; &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[[AppSensor_DetectionPoints#AE11|AE11]]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[https://capec.mitre.org/data/definitions/220.html 220]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt; &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt; &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt; &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[[AppSensor_DetectionPoints#SE1|SE1]]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[https://capec.mitre.org/data/definitions/221.html 221]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt; &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt; &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt; &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[[AppSensor_DetectionPoints#SE3|SE3]]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[https://capec.mitre.org/data/definitions/261.html 261]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt; &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt; &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt; &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[[AppSensor_DetectionPoints#SE4|SE4]]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt; &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt; &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt; &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt; &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[[AppSensor_DetectionPoints#SE5|SE5]]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt; &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt; &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt; &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt; &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[[AppSensor_DetectionPoints#SE6|SE6]]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt; &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt; &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt; &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt; &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[[AppSensor_DetectionPoints#IE2|IE2]]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt; &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt; &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt; &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt; &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[[AppSensor_DetectionPoints#IE3|IE3]]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt; &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt; &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt; &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt; &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[[AppSensor_DetectionPoints#IE4|IE4]]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt; &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt; &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt; &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt; &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[[AppSensor_DetectionPoints#HT1|HT1]]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt; &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt; &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt; &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt; &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[[AppSensor_DetectionPoints#HT2|HT2]]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt; &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt; &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt; &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt; &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[[AppSensor_DetectionPoints#HT3|HT3]]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt; &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;padding:5px;background:LightGray;color:White;font-weight:bold;&amp;quot;&amp;gt;[[Cornucopia_-_Ecommerce_Website_-_VE_3|« Previous Card]] &amp;lt;span style=&amp;quot;padding-left:10px;padding-right:10px;&amp;quot;&amp;gt;|&amp;lt;/span&amp;gt;  [[Cornucopia_-_Ecommerce_Website_-_VE|Data Validation and Encoding]] &amp;lt;span style=&amp;quot;padding-left:10px;padding-right:10px;&amp;quot;&amp;gt;|&amp;lt;/span&amp;gt; [[Cornucopia_-_Ecommerce_Website_-_VE_5|Next Card »]] &amp;lt;/div&amp;gt;&lt;/div&gt;</summary>
		<author><name>Dariodf</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cornucopia_-_Ecommerce_Website_-_AT_7&amp;diff=212061</id>
		<title>Cornucopia - Ecommerce Website - AT 7</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cornucopia_-_Ecommerce_Website_-_AT_7&amp;diff=212061"/>
				<updated>2016-03-29T19:50:51Z</updated>
		
		<summary type="html">&lt;p&gt;Dariodf: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{DISPLAYTITLE:&amp;lt;span style=&amp;quot;padding:2px 5px 0px 5px;color:white;background:#73abcc;&amp;quot;&amp;gt;Cornucopia - Ecommerce Website - AT 7&amp;lt;/span&amp;gt;}}&lt;br /&gt;
[[File:Cornucopia_-_Ecommerce_Website_AT_7.png|frame|right]]&lt;br /&gt;
'''Suit:''' [[Cornucopia_-_Ecommerce_Website_-_AT|Authentication]]&lt;br /&gt;
&lt;br /&gt;
'''Card/Value:''' 7&lt;br /&gt;
&lt;br /&gt;
=== Description: ===&lt;br /&gt;
&lt;br /&gt;
Cecilia can use brute force and dictionary attacks against one or many accounts without limit, or these attacks are simplified due to insufficient complexity, length, expiration and re-use requirements for passwords.&lt;br /&gt;
&lt;br /&gt;
=== Technical Note: ===&lt;br /&gt;
&lt;br /&gt;
Attacks should be prevented from being able to obtain valid account credentials by using the application in an unintended manner. This includes credential cracking (identifying valid login credentials by trying different values for usernames and/or passwords) and credential stuffing (mass log in attempts used to verify the validity of stolen username/password pairs).&lt;br /&gt;
&lt;br /&gt;
NB: This card relates to '''passwords'''. See [[Cornucopia_-_Ecommerce_Website_-_AT_4|AT 4]] for the similar user name attacks.&lt;br /&gt;
&lt;br /&gt;
=== References: ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;table class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center;&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;th&amp;gt;OWASP SCP&amp;lt;/th&amp;gt;&lt;br /&gt;
&amp;lt;th&amp;gt;OWASP ASVS&amp;lt;/th&amp;gt;&lt;br /&gt;
&amp;lt;th&amp;gt;OWASP AppSensor&amp;lt;/th&amp;gt;&lt;br /&gt;
&amp;lt;th&amp;gt;CAPEC&amp;lt;/th&amp;gt;&lt;br /&gt;
&amp;lt;th&amp;gt;SAFECODE&amp;lt;/th&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#33|33]]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[[OWASP_Application_Security_Verification_Standard#2.7|2.7]]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[[AppSensor_DetectionPoints#AE2|AE2]]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[https://capec.mitre.org/data/definitions/2.html 2]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[[SAFECode_Practical_Security_Stories#27|27]]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#38|38]]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[[OWASP_Application_Security_Verification_Standard#2.20|2.20]]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[[AppSensor_DetectionPoints#AE3|AE3]]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[https://capec.mitre.org/data/definitions/16.html 16]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#39|39]]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[[OWASP_Application_Security_Verification_Standard#2.25|2.25]]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#41|41]]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#50|50]]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#53|53]]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;padding:5px;background:LightGray;color:White;font-weight:bold;&amp;quot;&amp;gt;[[Cornucopia_-_Ecommerce_Website_-_AT_6|« Previous Card]] &amp;lt;span style=&amp;quot;padding-left:10px;padding-right:10px;&amp;quot;&amp;gt;|&amp;lt;/span&amp;gt;  [[Cornucopia_-_Ecommerce_Website_-_AT|Authentication]] &amp;lt;span style=&amp;quot;padding-left:10px;padding-right:10px;&amp;quot;&amp;gt;|&amp;lt;/span&amp;gt; [[Cornucopia_-_Ecommerce_Website_-_AT_8|Next Card »]] &amp;lt;/div&amp;gt;&lt;/div&gt;</summary>
		<author><name>Dariodf</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cornucopia_-_Ecommerce_Website_Edition_-_Wiki_Deck&amp;diff=207229</id>
		<title>Cornucopia - Ecommerce Website Edition - Wiki Deck</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cornucopia_-_Ecommerce_Website_Edition_-_Wiki_Deck&amp;diff=207229"/>
				<updated>2016-01-21T17:06:05Z</updated>
		
		<summary type="html">&lt;p&gt;Dariodf: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__NOTOC__&lt;br /&gt;
Wiki card deck conceived and created by Darío De Filippis.&lt;br /&gt;
&lt;br /&gt;
= Versioning =&lt;br /&gt;
&lt;br /&gt;
This wiki deck relates to version 1.10 EN of [https://www.owasp.org/index.php/OWASP_Cornucopia OWASP Cornucopia] Ecommerce Website Edition (currently the only edition). The cards are available in other formats (DOC, PDF, print) from the main project pages.&lt;br /&gt;
&lt;br /&gt;
The cross-references relate to the following versions of other OWASP and external resources:&lt;br /&gt;
&lt;br /&gt;
* OWASP SCP [[OWASP_Secure_Coding_Practices_Checklist]] v2&lt;br /&gt;
* OWASP ASVS [[OWASP_Application_Security_Verification_Standard]] v2 (2014)&lt;br /&gt;
* OWASP AppSensor [[AppSensor_DetectionPoints]]&lt;br /&gt;
* CAPEC [https://capec.mitre.org Mitre Common Attack Pattern Enumeration and Classification] v1.7.1&lt;br /&gt;
* SAFECode [[SAFECode_Practical_Security_Stories|SAFECode Practical Security Stories and Security Tasks for Agile Development Environments]] July 2012&lt;br /&gt;
&lt;br /&gt;
= Deck =&lt;br /&gt;
&lt;br /&gt;
== &amp;lt;span style=&amp;quot;padding:5px;background:#929292;font-weight:bold;&amp;quot;&amp;gt; [[Cornucopia_-_Ecommerce_Website_-_VE|&amp;lt;span style=&amp;quot;color:white;&amp;quot;&amp;gt;Data validation and encoding (VE)&amp;lt;/span&amp;gt;]]&amp;lt;/span&amp;gt; ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;font-size:125%;letter-spacing: 0.15em;&amp;quot;&amp;gt;[[Cornucopia_-_Ecommerce_Website_-_VE_2|2]] [[Cornucopia_-_Ecommerce_Website_-_VE_3|3]] [[Cornucopia_-_Ecommerce_Website_-_VE_4|4]] [[Cornucopia_-_Ecommerce_Website_-_VE_5|5]] [[Cornucopia_-_Ecommerce_Website_-_VE_6|6]] [[Cornucopia_-_Ecommerce_Website_-_VE_7|7]] [[Cornucopia_-_Ecommerce_Website_-_VE_8|8]] [[Cornucopia_-_Ecommerce_Website_-_VE_9|9]] &amp;lt;span style=&amp;quot;letter-spacing: 0;&amp;quot;&amp;gt;[[Cornucopia_-_Ecommerce_Website_-_VE_10|10]]&amp;lt;/span&amp;gt; [[Cornucopia_-_Ecommerce_Website_-_VE_J|J]] [[Cornucopia_-_Ecommerce_Website_-_VE_Q|Q]] [[Cornucopia_-_Ecommerce_Website_-_VE_K|K]] [[Cornucopia_-_Ecommerce_Website_-_VE_A|A]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== &amp;lt;span style=&amp;quot;padding:5px;background:#73abcc;font-weight:bold;&amp;quot;&amp;gt; [[Cornucopia_-_Ecommerce_Website_-_AT|&amp;lt;span style=&amp;quot;color:white;&amp;quot;&amp;gt;Authentication (AT)&amp;lt;/span&amp;gt;]]&amp;lt;/span&amp;gt; ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;font-size:125%;letter-spacing: 0.15em;&amp;quot;&amp;gt;[[Cornucopia_-_Ecommerce_Website_-_AT_2|2]] [[Cornucopia_-_Ecommerce_Website_-_AT_3|3]] [[Cornucopia_-_Ecommerce_Website_-_AT_4|4]] [[Cornucopia_-_Ecommerce_Website_-_AT_5|5]] [[Cornucopia_-_Ecommerce_Website_-_AT_6|6]] [[Cornucopia_-_Ecommerce_Website_-_AT_7|7]] [[Cornucopia_-_Ecommerce_Website_-_AT_8|8]] [[Cornucopia_-_Ecommerce_Website_-_AT_9|9]] &amp;lt;span style=&amp;quot;letter-spacing: 0;&amp;quot;&amp;gt;[[Cornucopia_-_Ecommerce_Website_-_AT_10|10]]&amp;lt;/span&amp;gt; [[Cornucopia_-_Ecommerce_Website_-_AT_J|J]] [[Cornucopia_-_Ecommerce_Website_-_AT_Q|Q]] [[Cornucopia_-_Ecommerce_Website_-_AT_K|K]] [[Cornucopia_-_Ecommerce_Website_-_AT_A|A]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== &amp;lt;span style=&amp;quot;padding:5px;background:#98c477;font-weight:bold;&amp;quot;&amp;gt; [[Cornucopia_-_Ecommerce_Website_-_SM|&amp;lt;span style=&amp;quot;color:white;&amp;quot;&amp;gt;Session management (SM)&amp;lt;/span&amp;gt;]]&amp;lt;/span&amp;gt; ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;font-size:125%;letter-spacing: 0.15em;&amp;quot;&amp;gt;[[Cornucopia_-_Ecommerce_Website_-_SM_2|2]] [[Cornucopia_-_Ecommerce_Website_-_SM_3|3]] [[Cornucopia_-_Ecommerce_Website_-_SM_4|4]] [[Cornucopia_-_Ecommerce_Website_-_SM_5|5]] [[Cornucopia_-_Ecommerce_Website_-_SM_6|6]] [[Cornucopia_-_Ecommerce_Website_-_SM_7|7]] [[Cornucopia_-_Ecommerce_Website_-_SM_8|8]] [[Cornucopia_-_Ecommerce_Website_-_SM_9|9]] &amp;lt;span style=&amp;quot;letter-spacing: 0;&amp;quot;&amp;gt;[[Cornucopia_-_Ecommerce_Website_-_SM_10|10]]&amp;lt;/span&amp;gt; [[Cornucopia_-_Ecommerce_Website_-_SM_J|J]] [[Cornucopia_-_Ecommerce_Website_-_SM_Q|Q]] [[Cornucopia_-_Ecommerce_Website_-_SM_K|K]] [[Cornucopia_-_Ecommerce_Website_-_SM_A|A]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== &amp;lt;span style=&amp;quot;padding:5px;background:#d9c049;font-weight:bold;&amp;quot;&amp;gt; [[Cornucopia_-_Ecommerce_Website_-_AZ|&amp;lt;span style=&amp;quot;color:white;&amp;quot;&amp;gt;Authorization (AZ)&amp;lt;/span&amp;gt;]]&amp;lt;/span&amp;gt; ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;font-size:125%;letter-spacing: 0.15em;&amp;quot;&amp;gt;[[Cornucopia_-_Ecommerce_Website_-_AZ_2|2]] [[Cornucopia_-_Ecommerce_Website_-_AZ_3|3]] [[Cornucopia_-_Ecommerce_Website_-_AZ_4|4]] [[Cornucopia_-_Ecommerce_Website_-_AZ_5|5]] [[Cornucopia_-_Ecommerce_Website_-_AZ_6|6]] [[Cornucopia_-_Ecommerce_Website_-_AZ_7|7]] [[Cornucopia_-_Ecommerce_Website_-_AZ_8|8]] [[Cornucopia_-_Ecommerce_Website_-_AZ_9|9]] &amp;lt;span style=&amp;quot;letter-spacing: 0;&amp;quot;&amp;gt;[[Cornucopia_-_Ecommerce_Website_-_AZ_10|10]]&amp;lt;/span&amp;gt; [[Cornucopia_-_Ecommerce_Website_-_AZ_J|J]] [[Cornucopia_-_Ecommerce_Website_-_AZ_Q|Q]] [[Cornucopia_-_Ecommerce_Website_-_AZ_K|K]] [[Cornucopia_-_Ecommerce_Website_-_AZ_A|A]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== &amp;lt;span style=&amp;quot;padding:5px;background:#a395ca;font-weight:bold;&amp;quot;&amp;gt; [[Cornucopia_-_Ecommerce_Website_-_CR|&amp;lt;span style=&amp;quot;color:white;&amp;quot;&amp;gt;Cryptography (CR)&amp;lt;/span&amp;gt;]]&amp;lt;/span&amp;gt; ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;font-size:125%;letter-spacing: 0.15em;&amp;quot;&amp;gt;[[Cornucopia_-_Ecommerce_Website_-_CR_2|2]] [[Cornucopia_-_Ecommerce_Website_-_CR_3|3]] [[Cornucopia_-_Ecommerce_Website_-_CR_4|4]] [[Cornucopia_-_Ecommerce_Website_-_CR_5|5]] [[Cornucopia_-_Ecommerce_Website_-_CR_6|6]] [[Cornucopia_-_Ecommerce_Website_-_CR_7|7]] [[Cornucopia_-_Ecommerce_Website_-_CR_8|8]] [[Cornucopia_-_Ecommerce_Website_-_CR_9|9]] &amp;lt;span style=&amp;quot;letter-spacing: 0;&amp;quot;&amp;gt;[[Cornucopia_-_Ecommerce_Website_-_CR_10|10]]&amp;lt;/span&amp;gt; [[Cornucopia_-_Ecommerce_Website_-_CR_J|J]] [[Cornucopia_-_Ecommerce_Website_-_CR_Q|Q]] [[Cornucopia_-_Ecommerce_Website_-_CR_K|K]] [[Cornucopia_-_Ecommerce_Website_-_CR_A|A]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== &amp;lt;span style=&amp;quot;padding:5px;background:#17365d;font-weight:bold;&amp;quot;&amp;gt; [[Cornucopia_-_Ecommerce_Website_-_C|&amp;lt;span style=&amp;quot;color:white;&amp;quot;&amp;gt;Cornucopia (C)&amp;lt;/span&amp;gt;]]&amp;lt;/span&amp;gt; ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;font-size:125%;letter-spacing: 0.15em;&amp;quot;&amp;gt;[[Cornucopia_-_Ecommerce_Website_-_C_2|2]] [[Cornucopia_-_Ecommerce_Website_-_C_3|3]] [[Cornucopia_-_Ecommerce_Website_-_C_4|4]] [[Cornucopia_-_Ecommerce_Website_-_C_5|5]] [[Cornucopia_-_Ecommerce_Website_-_C_6|6]] [[Cornucopia_-_Ecommerce_Website_-_C_7|7]] [[Cornucopia_-_Ecommerce_Website_-_C_8|8]] [[Cornucopia_-_Ecommerce_Website_-_C_9|9]] &amp;lt;span style=&amp;quot;letter-spacing: 0;&amp;quot;&amp;gt;[[Cornucopia_-_Ecommerce_Website_-_C_10|10]]&amp;lt;/span&amp;gt; [[Cornucopia_-_Ecommerce_Website_-_C_J|J]] [[Cornucopia_-_Ecommerce_Website_-_C_Q|Q]] [[Cornucopia_-_Ecommerce_Website_-_C_K|K]] [[Cornucopia_-_Ecommerce_Website_-_C_A|A]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== &amp;lt;span style=&amp;quot;padding:5px;background:#fbbb7b;font-weight:bold;&amp;quot;&amp;gt; [[Cornucopia_-_Ecommerce_Website_-_W|&amp;lt;span style=&amp;quot;color:white;&amp;quot;&amp;gt;Wild Card (W)&amp;lt;/span&amp;gt;]]&amp;lt;/span&amp;gt; ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;font-size:125%;&amp;quot;&amp;gt;[[Cornucopia_-_Ecommerce_Website_-_W_Joker_A|Joker (A)]]&amp;lt;span style=&amp;quot;letter-spacing: 0.15em;&amp;quot;&amp;gt; &amp;lt;/span&amp;gt;[[Cornucopia_-_Ecommerce_Website_-_W_Joker_B|Joker (B)]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category: Attack]] [[Category: Threat_Modeling]]  [[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]] [[Category:OWASP_Document]] [[Category:SAMM-SR-2]] [[Category:SAMM-TA-1]] [[Category:SAMM-EG-2]]&lt;/div&gt;</summary>
		<author><name>Dariodf</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cornucopia_-_Ecommerce_Website_Edition_-_Wiki_Deck&amp;diff=207228</id>
		<title>Cornucopia - Ecommerce Website Edition - Wiki Deck</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cornucopia_-_Ecommerce_Website_Edition_-_Wiki_Deck&amp;diff=207228"/>
				<updated>2016-01-21T17:05:45Z</updated>
		
		<summary type="html">&lt;p&gt;Dariodf: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__NOTOC__&lt;br /&gt;
Wiki card deck conceived and created by Darío De Filippis.&lt;br /&gt;
&lt;br /&gt;
= Versioning =&lt;br /&gt;
&lt;br /&gt;
This wiki deck relates to version 1.10 EN of [https://www.owasp.org/index.php/OWASP_Cornucopia OWASP Cornucopia] Ecommerce Website Edition (currently the only edition). The cards are available in other formats (DOC, PDF, print) from the main project pages.&lt;br /&gt;
&lt;br /&gt;
The cross-references relate to the following versions of other OWASP and external resources:&lt;br /&gt;
&lt;br /&gt;
* OWASP SCP [[OWASP_Secure_Coding_Practices_Checklist]] v2&lt;br /&gt;
* OWASP ASVS [[OWASP_Application_Security_Verification_Standard]] v2 (2014)&lt;br /&gt;
* OWASP AppSensor [[OWASP_AppSensor_DetectionPoints]]&lt;br /&gt;
* CAPEC [https://capec.mitre.org Mitre Common Attack Pattern Enumeration and Classification] v1.7.1&lt;br /&gt;
* SAFECode [[SAFECode_Practical_Security_Stories|SAFECode Practical Security Stories and Security Tasks for Agile Development Environments]] July 2012&lt;br /&gt;
&lt;br /&gt;
= Deck =&lt;br /&gt;
&lt;br /&gt;
== &amp;lt;span style=&amp;quot;padding:5px;background:#929292;font-weight:bold;&amp;quot;&amp;gt; [[Cornucopia_-_Ecommerce_Website_-_VE|&amp;lt;span style=&amp;quot;color:white;&amp;quot;&amp;gt;Data validation and encoding (VE)&amp;lt;/span&amp;gt;]]&amp;lt;/span&amp;gt; ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;font-size:125%;letter-spacing: 0.15em;&amp;quot;&amp;gt;[[Cornucopia_-_Ecommerce_Website_-_VE_2|2]] [[Cornucopia_-_Ecommerce_Website_-_VE_3|3]] [[Cornucopia_-_Ecommerce_Website_-_VE_4|4]] [[Cornucopia_-_Ecommerce_Website_-_VE_5|5]] [[Cornucopia_-_Ecommerce_Website_-_VE_6|6]] [[Cornucopia_-_Ecommerce_Website_-_VE_7|7]] [[Cornucopia_-_Ecommerce_Website_-_VE_8|8]] [[Cornucopia_-_Ecommerce_Website_-_VE_9|9]] &amp;lt;span style=&amp;quot;letter-spacing: 0;&amp;quot;&amp;gt;[[Cornucopia_-_Ecommerce_Website_-_VE_10|10]]&amp;lt;/span&amp;gt; [[Cornucopia_-_Ecommerce_Website_-_VE_J|J]] [[Cornucopia_-_Ecommerce_Website_-_VE_Q|Q]] [[Cornucopia_-_Ecommerce_Website_-_VE_K|K]] [[Cornucopia_-_Ecommerce_Website_-_VE_A|A]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== &amp;lt;span style=&amp;quot;padding:5px;background:#73abcc;font-weight:bold;&amp;quot;&amp;gt; [[Cornucopia_-_Ecommerce_Website_-_AT|&amp;lt;span style=&amp;quot;color:white;&amp;quot;&amp;gt;Authentication (AT)&amp;lt;/span&amp;gt;]]&amp;lt;/span&amp;gt; ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;font-size:125%;letter-spacing: 0.15em;&amp;quot;&amp;gt;[[Cornucopia_-_Ecommerce_Website_-_AT_2|2]] [[Cornucopia_-_Ecommerce_Website_-_AT_3|3]] [[Cornucopia_-_Ecommerce_Website_-_AT_4|4]] [[Cornucopia_-_Ecommerce_Website_-_AT_5|5]] [[Cornucopia_-_Ecommerce_Website_-_AT_6|6]] [[Cornucopia_-_Ecommerce_Website_-_AT_7|7]] [[Cornucopia_-_Ecommerce_Website_-_AT_8|8]] [[Cornucopia_-_Ecommerce_Website_-_AT_9|9]] &amp;lt;span style=&amp;quot;letter-spacing: 0;&amp;quot;&amp;gt;[[Cornucopia_-_Ecommerce_Website_-_AT_10|10]]&amp;lt;/span&amp;gt; [[Cornucopia_-_Ecommerce_Website_-_AT_J|J]] [[Cornucopia_-_Ecommerce_Website_-_AT_Q|Q]] [[Cornucopia_-_Ecommerce_Website_-_AT_K|K]] [[Cornucopia_-_Ecommerce_Website_-_AT_A|A]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== &amp;lt;span style=&amp;quot;padding:5px;background:#98c477;font-weight:bold;&amp;quot;&amp;gt; [[Cornucopia_-_Ecommerce_Website_-_SM|&amp;lt;span style=&amp;quot;color:white;&amp;quot;&amp;gt;Session management (SM)&amp;lt;/span&amp;gt;]]&amp;lt;/span&amp;gt; ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;font-size:125%;letter-spacing: 0.15em;&amp;quot;&amp;gt;[[Cornucopia_-_Ecommerce_Website_-_SM_2|2]] [[Cornucopia_-_Ecommerce_Website_-_SM_3|3]] [[Cornucopia_-_Ecommerce_Website_-_SM_4|4]] [[Cornucopia_-_Ecommerce_Website_-_SM_5|5]] [[Cornucopia_-_Ecommerce_Website_-_SM_6|6]] [[Cornucopia_-_Ecommerce_Website_-_SM_7|7]] [[Cornucopia_-_Ecommerce_Website_-_SM_8|8]] [[Cornucopia_-_Ecommerce_Website_-_SM_9|9]] &amp;lt;span style=&amp;quot;letter-spacing: 0;&amp;quot;&amp;gt;[[Cornucopia_-_Ecommerce_Website_-_SM_10|10]]&amp;lt;/span&amp;gt; [[Cornucopia_-_Ecommerce_Website_-_SM_J|J]] [[Cornucopia_-_Ecommerce_Website_-_SM_Q|Q]] [[Cornucopia_-_Ecommerce_Website_-_SM_K|K]] [[Cornucopia_-_Ecommerce_Website_-_SM_A|A]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== &amp;lt;span style=&amp;quot;padding:5px;background:#d9c049;font-weight:bold;&amp;quot;&amp;gt; [[Cornucopia_-_Ecommerce_Website_-_AZ|&amp;lt;span style=&amp;quot;color:white;&amp;quot;&amp;gt;Authorization (AZ)&amp;lt;/span&amp;gt;]]&amp;lt;/span&amp;gt; ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;font-size:125%;letter-spacing: 0.15em;&amp;quot;&amp;gt;[[Cornucopia_-_Ecommerce_Website_-_AZ_2|2]] [[Cornucopia_-_Ecommerce_Website_-_AZ_3|3]] [[Cornucopia_-_Ecommerce_Website_-_AZ_4|4]] [[Cornucopia_-_Ecommerce_Website_-_AZ_5|5]] [[Cornucopia_-_Ecommerce_Website_-_AZ_6|6]] [[Cornucopia_-_Ecommerce_Website_-_AZ_7|7]] [[Cornucopia_-_Ecommerce_Website_-_AZ_8|8]] [[Cornucopia_-_Ecommerce_Website_-_AZ_9|9]] &amp;lt;span style=&amp;quot;letter-spacing: 0;&amp;quot;&amp;gt;[[Cornucopia_-_Ecommerce_Website_-_AZ_10|10]]&amp;lt;/span&amp;gt; [[Cornucopia_-_Ecommerce_Website_-_AZ_J|J]] [[Cornucopia_-_Ecommerce_Website_-_AZ_Q|Q]] [[Cornucopia_-_Ecommerce_Website_-_AZ_K|K]] [[Cornucopia_-_Ecommerce_Website_-_AZ_A|A]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== &amp;lt;span style=&amp;quot;padding:5px;background:#a395ca;font-weight:bold;&amp;quot;&amp;gt; [[Cornucopia_-_Ecommerce_Website_-_CR|&amp;lt;span style=&amp;quot;color:white;&amp;quot;&amp;gt;Cryptography (CR)&amp;lt;/span&amp;gt;]]&amp;lt;/span&amp;gt; ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;font-size:125%;letter-spacing: 0.15em;&amp;quot;&amp;gt;[[Cornucopia_-_Ecommerce_Website_-_CR_2|2]] [[Cornucopia_-_Ecommerce_Website_-_CR_3|3]] [[Cornucopia_-_Ecommerce_Website_-_CR_4|4]] [[Cornucopia_-_Ecommerce_Website_-_CR_5|5]] [[Cornucopia_-_Ecommerce_Website_-_CR_6|6]] [[Cornucopia_-_Ecommerce_Website_-_CR_7|7]] [[Cornucopia_-_Ecommerce_Website_-_CR_8|8]] [[Cornucopia_-_Ecommerce_Website_-_CR_9|9]] &amp;lt;span style=&amp;quot;letter-spacing: 0;&amp;quot;&amp;gt;[[Cornucopia_-_Ecommerce_Website_-_CR_10|10]]&amp;lt;/span&amp;gt; [[Cornucopia_-_Ecommerce_Website_-_CR_J|J]] [[Cornucopia_-_Ecommerce_Website_-_CR_Q|Q]] [[Cornucopia_-_Ecommerce_Website_-_CR_K|K]] [[Cornucopia_-_Ecommerce_Website_-_CR_A|A]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== &amp;lt;span style=&amp;quot;padding:5px;background:#17365d;font-weight:bold;&amp;quot;&amp;gt; [[Cornucopia_-_Ecommerce_Website_-_C|&amp;lt;span style=&amp;quot;color:white;&amp;quot;&amp;gt;Cornucopia (C)&amp;lt;/span&amp;gt;]]&amp;lt;/span&amp;gt; ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;font-size:125%;letter-spacing: 0.15em;&amp;quot;&amp;gt;[[Cornucopia_-_Ecommerce_Website_-_C_2|2]] [[Cornucopia_-_Ecommerce_Website_-_C_3|3]] [[Cornucopia_-_Ecommerce_Website_-_C_4|4]] [[Cornucopia_-_Ecommerce_Website_-_C_5|5]] [[Cornucopia_-_Ecommerce_Website_-_C_6|6]] [[Cornucopia_-_Ecommerce_Website_-_C_7|7]] [[Cornucopia_-_Ecommerce_Website_-_C_8|8]] [[Cornucopia_-_Ecommerce_Website_-_C_9|9]] &amp;lt;span style=&amp;quot;letter-spacing: 0;&amp;quot;&amp;gt;[[Cornucopia_-_Ecommerce_Website_-_C_10|10]]&amp;lt;/span&amp;gt; [[Cornucopia_-_Ecommerce_Website_-_C_J|J]] [[Cornucopia_-_Ecommerce_Website_-_C_Q|Q]] [[Cornucopia_-_Ecommerce_Website_-_C_K|K]] [[Cornucopia_-_Ecommerce_Website_-_C_A|A]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== &amp;lt;span style=&amp;quot;padding:5px;background:#fbbb7b;font-weight:bold;&amp;quot;&amp;gt; [[Cornucopia_-_Ecommerce_Website_-_W|&amp;lt;span style=&amp;quot;color:white;&amp;quot;&amp;gt;Wild Card (W)&amp;lt;/span&amp;gt;]]&amp;lt;/span&amp;gt; ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;font-size:125%;&amp;quot;&amp;gt;[[Cornucopia_-_Ecommerce_Website_-_W_Joker_A|Joker (A)]]&amp;lt;span style=&amp;quot;letter-spacing: 0.15em;&amp;quot;&amp;gt; &amp;lt;/span&amp;gt;[[Cornucopia_-_Ecommerce_Website_-_W_Joker_B|Joker (B)]]&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category: Attack]] [[Category: Threat_Modeling]]  [[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]] [[Category:OWASP_Document]] [[Category:SAMM-SR-2]] [[Category:SAMM-TA-1]] [[Category:SAMM-EG-2]]&lt;/div&gt;</summary>
		<author><name>Dariodf</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cornucopia_-_Ecommerce_Website_-_W_Joker_B&amp;diff=207225</id>
		<title>Cornucopia - Ecommerce Website - W Joker B</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cornucopia_-_Ecommerce_Website_-_W_Joker_B&amp;diff=207225"/>
				<updated>2016-01-21T16:32:24Z</updated>
		
		<summary type="html">&lt;p&gt;Dariodf: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{DISPLAYTITLE:&amp;lt;span style=&amp;quot;padding:2px 5px 0px 5px;color:white;background:#fbbb7b;&amp;quot;&amp;gt;Cornucopia - Ecommerce Website - WC J&amp;lt;/span&amp;gt;}}&lt;br /&gt;
[[File:Cornucopia_-_Ecommerce_Website_W_Joker_B.png|frame|right]]&lt;br /&gt;
'''Suit:''' [[Cornucopia_-_Ecommerce_Website_-_W|Wild Card]]&lt;br /&gt;
&lt;br /&gt;
'''Card/Value:''' Joker&lt;br /&gt;
&lt;br /&gt;
=== Description: ===&lt;br /&gt;
&lt;br /&gt;
Bob can influence, alter or affect the application so that it no longer complies with legal, regulatory, contractual or other organizational mandates.&lt;br /&gt;
&lt;br /&gt;
=== Technical Note: ===&lt;br /&gt;
&lt;br /&gt;
Most ecommerce applications will be subject to various legal, regulatory, contractual or other organizational mandates. These are likely to include requirements for data protection/privacy and payment card security. An unapproved change, or application compromise, could mean the ecommerce application is no longer in compliance, or that compliance reporting requirements change. Some examples are:&lt;br /&gt;
* An undocumented installed component has a vulnerability announced.&lt;br /&gt;
* The server hosting the ecommerce application makes an unapproved connection to another system.&lt;br /&gt;
* The fully outsourced payment form template is modified to include code from the merchant's server.&lt;br /&gt;
* Personal data relating to an individual is used for a purpose the individual has not consented to.&lt;br /&gt;
* An unauthorised change to configuration data such that some component/service is no longer configured adequately.&lt;br /&gt;
* Unapproved/insecure services/applications are installed/enabled.&lt;br /&gt;
* The terms of service, or privacy statement, are modified without approval.&lt;br /&gt;
* Personal data is inadvertently mixed with business contact data.&lt;br /&gt;
* A scheduled process is accidentally disabled so that quarterly data destruction is stopped, meaning the application no longer complies with the data retention and disposal policy.&lt;br /&gt;
&lt;br /&gt;
Consider:&lt;br /&gt;
* What could change that affects compliance?&lt;br /&gt;
* How will the application detect this?&lt;br /&gt;
* What is the incident response process for these?&lt;br /&gt;
&lt;br /&gt;
=== References: ===&lt;br /&gt;
&lt;br /&gt;
Examine vulnerabilities and discover how they can be fixed using training applications in the free OWASP Broken Web Applications VM, or using the online challenges in the free Hacking Lab.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;padding:5px;background:LightGray;color:White;font-weight:bold;&amp;quot;&amp;gt;[[Cornucopia_-_Ecommerce_Website_-_W_Joker_A|« Previous Card]] &amp;lt;span style=&amp;quot;padding-left:10px;padding-right:10px;&amp;quot;&amp;gt;|&amp;lt;/span&amp;gt;  [[Cornucopia_-_Ecommerce_Website_-_W|Wild Card]] &amp;lt;span style=&amp;quot;padding-left:10px;padding-right:10px;&amp;quot;&amp;gt;|&amp;lt;/span&amp;gt; [[Cornucopia_-_Ecommerce_Website_-_VE_2|Next Card »]] &amp;lt;/div&amp;gt;&lt;/div&gt;</summary>
		<author><name>Dariodf</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cornucopia_-_Ecommerce_Website_-_W_Joker_A&amp;diff=207224</id>
		<title>Cornucopia - Ecommerce Website - W Joker A</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cornucopia_-_Ecommerce_Website_-_W_Joker_A&amp;diff=207224"/>
				<updated>2016-01-21T16:31:55Z</updated>
		
		<summary type="html">&lt;p&gt;Dariodf: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{DISPLAYTITLE:&amp;lt;span style=&amp;quot;padding:2px 5px 0px 5px;color:white;background:#fbbb7b;&amp;quot;&amp;gt;Cornucopia - Ecommerce Website - W J&amp;lt;/span&amp;gt;}}&lt;br /&gt;
[[File:Cornucopia_-_Ecommerce_Website_W_Joker_A.png|frame|right]]&lt;br /&gt;
'''Suit:''' [[Cornucopia_-_Ecommerce_Website_-_W|Wild Card]]&lt;br /&gt;
&lt;br /&gt;
'''Card/Value:''' Joker&lt;br /&gt;
&lt;br /&gt;
=== Description: ===&lt;br /&gt;
&lt;br /&gt;
Alice can utilize the application to attack users' systems and data.&lt;br /&gt;
&lt;br /&gt;
=== Technical Note: ===&lt;br /&gt;
&lt;br /&gt;
Consider how the application's normal functionality might be used to the disbenefit of another application, of some or all users, of another party, or even of society. This may include:&lt;br /&gt;
* Performing denial of service.&lt;br /&gt;
* Hosting/distribution of unapproved content (e.g. videos, photos, malware).&lt;br /&gt;
* Generating of spam messages.&lt;br /&gt;
* Hosting unapproved application code (e.g. as a command and control server, or as a bot).&lt;br /&gt;
* Reflecting an attack against another system.&lt;br /&gt;
* Attacking another internal system (e.g. databases, internal network).&lt;br /&gt;
&lt;br /&gt;
=== References: ===&lt;br /&gt;
&lt;br /&gt;
Have you thought about becoming an individual OWASP member? All tools, guidance and local meetings are free for everyone, but individual membership helps support OWASP’s work.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;padding:5px;background:LightGray;color:White;font-weight:bold;&amp;quot;&amp;gt;[[Cornucopia_-_Ecommerce_Website_-_C_A|« Previous Card]] &amp;lt;span style=&amp;quot;padding-left:10px;padding-right:10px;&amp;quot;&amp;gt;|&amp;lt;/span&amp;gt;  [[Cornucopia_-_Ecommerce_Website_-_W|Wild Card]] &amp;lt;span style=&amp;quot;padding-left:10px;padding-right:10px;&amp;quot;&amp;gt;|&amp;lt;/span&amp;gt; [[Cornucopia_-_Ecommerce_Website_-_W_Joker_B|Next Card »]] &amp;lt;/div&amp;gt;&lt;/div&gt;</summary>
		<author><name>Dariodf</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cornucopia_-_Ecommerce_Website_-_C_A&amp;diff=207223</id>
		<title>Cornucopia - Ecommerce Website - C A</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cornucopia_-_Ecommerce_Website_-_C_A&amp;diff=207223"/>
				<updated>2016-01-21T16:31:31Z</updated>
		
		<summary type="html">&lt;p&gt;Dariodf: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{DISPLAYTITLE:&amp;lt;span style=&amp;quot;padding:2px 5px 0px 5px;color:white;background:#17365d;&amp;quot;&amp;gt;Cornucopia - Ecommerce Website - C A&amp;lt;/span&amp;gt;}}&lt;br /&gt;
[[File:Cornucopia_-_Ecommerce_Website_C_A.png|frame|right]]&lt;br /&gt;
'''Suit:''' [[Cornucopia_-_Ecommerce_Website_-_C|Cornucopia]]&lt;br /&gt;
&lt;br /&gt;
'''Card/Value:''' A&lt;br /&gt;
&lt;br /&gt;
=== Description: ===&lt;br /&gt;
&lt;br /&gt;
You have invented a new attack of any type.&lt;br /&gt;
&lt;br /&gt;
=== Technical Note: ===&lt;br /&gt;
&lt;br /&gt;
Players can discuss any type of attack they think might be possible against the assessment target. It does not matter if the attack relates to another suit or any other card, but if possible try to identify an attack that is fairly unique to the application/functionality/users.&lt;br /&gt;
&lt;br /&gt;
=== References: ===&lt;br /&gt;
&lt;br /&gt;
Read more about application security in OWASP’s free Guides on Requirements, Development, Code Review and Testing, the Cheat Sheet series, and the Open Software Assurance Maturity Model.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;padding:5px;background:LightGray;color:White;font-weight:bold;&amp;quot;&amp;gt;[[Cornucopia_-_Ecommerce_Website_-_C_K|« Previous Card]] &amp;lt;span style=&amp;quot;padding-left:10px;padding-right:10px;&amp;quot;&amp;gt;|&amp;lt;/span&amp;gt;  [[Cornucopia_-_Ecommerce_Website_-_C|Cornucopia]] &amp;lt;span style=&amp;quot;padding-left:10px;padding-right:10px;&amp;quot;&amp;gt;|&amp;lt;/span&amp;gt; [[Cornucopia_-_Ecommerce_Website_-_W_Joker_A|Next Card »]] &amp;lt;/div&amp;gt;&lt;/div&gt;</summary>
		<author><name>Dariodf</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cornucopia_-_Ecommerce_Website_-_C_K&amp;diff=207222</id>
		<title>Cornucopia - Ecommerce Website - C K</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cornucopia_-_Ecommerce_Website_-_C_K&amp;diff=207222"/>
				<updated>2016-01-21T16:31:20Z</updated>
		
		<summary type="html">&lt;p&gt;Dariodf: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{DISPLAYTITLE:&amp;lt;span style=&amp;quot;padding:2px 5px 0px 5px;color:white;background:#17365d;&amp;quot;&amp;gt;Cornucopia - Ecommerce Website - C K&amp;lt;/span&amp;gt;}}&lt;br /&gt;
[[File:Cornucopia_-_Ecommerce_Website_C_K.png|frame|right]]&lt;br /&gt;
'''Suit:''' [[Cornucopia_-_Ecommerce_Website_-_C|Cornucopia]]&lt;br /&gt;
&lt;br /&gt;
'''Card/Value:''' K&lt;br /&gt;
&lt;br /&gt;
=== Description: ===&lt;br /&gt;
&lt;br /&gt;
Gareth can utilize the application to deny service to some or all of its users.&lt;br /&gt;
&lt;br /&gt;
=== Technical Note: ===&lt;br /&gt;
&lt;br /&gt;
Application-layer denial of service and other activities that adversely affect the application's users. Includes:&lt;br /&gt;
* Account lockout.&lt;br /&gt;
* Spamming.&lt;br /&gt;
* Excessive resource consumption.&lt;br /&gt;
* Scalping.&lt;br /&gt;
* Sniping.&lt;br /&gt;
&lt;br /&gt;
Must involve the ecommerce application in the attack and thus excludes HTTP DoS (e.g. flood attacks, slow attacks).&lt;br /&gt;
&lt;br /&gt;
=== References: ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;table class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center;&amp;quot;&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;OWASP SCP&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;OWASP ASVS&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;OWASP AppSensor&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;CAPEC&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;SAFECODE&amp;lt;/th&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#41|41]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[AppSensor_DetectionPoints#UT1|UT1]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[https://capec.mitre.org/data/definitions/2.html 2]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[SAFECode_Practical_Security_Stories#1|1]]&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#55|55]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[AppSensor_DetectionPoints#UT2|UT2]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[https://capec.mitre.org/data/definitions/25.html 25]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[AppSensor_DetectionPoints#UT3|UT3]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[https://capec.mitre.org/data/definitions/119.html 119]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[AppSensor_DetectionPoints#UT4|UT4]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[AppSensor_DetectionPoints#STE3|STE3]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;padding:5px;background:LightGray;color:White;font-weight:bold;&amp;quot;&amp;gt;[[Cornucopia_-_Ecommerce_Website_-_C_Q|« Previous Card]] &amp;lt;span style=&amp;quot;padding-left:10px;padding-right:10px;&amp;quot;&amp;gt;|&amp;lt;/span&amp;gt;  [[Cornucopia_-_Ecommerce_Website_-_C|Cornucopia]] &amp;lt;span style=&amp;quot;padding-left:10px;padding-right:10px;&amp;quot;&amp;gt;|&amp;lt;/span&amp;gt; [[Cornucopia_-_Ecommerce_Website_-_C_A|Next Card »]] &amp;lt;/div&amp;gt;&lt;/div&gt;</summary>
		<author><name>Dariodf</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cornucopia_-_Ecommerce_Website_-_C_Q&amp;diff=207221</id>
		<title>Cornucopia - Ecommerce Website - C Q</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cornucopia_-_Ecommerce_Website_-_C_Q&amp;diff=207221"/>
				<updated>2016-01-21T16:31:10Z</updated>
		
		<summary type="html">&lt;p&gt;Dariodf: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{DISPLAYTITLE:&amp;lt;span style=&amp;quot;padding:2px 5px 0px 5px;color:white;background:#17365d;&amp;quot;&amp;gt;Cornucopia - Ecommerce Website - C Q&amp;lt;/span&amp;gt;}}&lt;br /&gt;
[[File:Cornucopia_-_Ecommerce_Website_C_Q.png|frame|right]]&lt;br /&gt;
'''Suit:''' [[Cornucopia_-_Ecommerce_Website_-_C|Cornucopia]]&lt;br /&gt;
&lt;br /&gt;
'''Card/Value:''' Q&lt;br /&gt;
&lt;br /&gt;
=== Description: ===&lt;br /&gt;
&lt;br /&gt;
Jim can undertake malicious, non-normal, actions without real-time detection and response by the application.&lt;br /&gt;
&lt;br /&gt;
=== Technical Note: ===&lt;br /&gt;
&lt;br /&gt;
Consider guidance provided by [[OWASP_AppSensor_Project|OWASP AppSensor real-time application level intrusion detection and response]].&lt;br /&gt;
&lt;br /&gt;
=== References: ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;table class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center;&amp;quot;&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;OWASP SCP&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;OWASP ASVS&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;OWASP AppSensor&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;CAPEC&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;SAFECODE&amp;lt;/th&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Application_Security_Verification_Standard#4.17|4.17]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[AppSensor_DetectionPoints|(All)]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[https://capec.mitre.org/ (All)]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[SAFECode_Practical_Security_Stories#1|1]]&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Application_Security_Verification_Standard#15.6|15.6]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[SAFECode_Practical_Security_Stories#27|27]]&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Application_Security_Verification_Standard#15.10|15.10]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;padding:5px;background:LightGray;color:White;font-weight:bold;&amp;quot;&amp;gt;[[Cornucopia_-_Ecommerce_Website_-_C_J|« Previous Card]] &amp;lt;span style=&amp;quot;padding-left:10px;padding-right:10px;&amp;quot;&amp;gt;|&amp;lt;/span&amp;gt;  [[Cornucopia_-_Ecommerce_Website_-_C|Cornucopia]] &amp;lt;span style=&amp;quot;padding-left:10px;padding-right:10px;&amp;quot;&amp;gt;|&amp;lt;/span&amp;gt; [[Cornucopia_-_Ecommerce_Website_-_C_K|Next Card »]] &amp;lt;/div&amp;gt;&lt;/div&gt;</summary>
		<author><name>Dariodf</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cornucopia_-_Ecommerce_Website_-_C_Q&amp;diff=207220</id>
		<title>Cornucopia - Ecommerce Website - C Q</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cornucopia_-_Ecommerce_Website_-_C_Q&amp;diff=207220"/>
				<updated>2016-01-21T16:31:03Z</updated>
		
		<summary type="html">&lt;p&gt;Dariodf: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{DISPLAYTITLE:&amp;lt;span style=&amp;quot;padding:2px 5px 0px 5px;color:white;background:#17365d;&amp;quot;&amp;gt;Cornucopia - Ecommerce Website - C Q&amp;lt;/span&amp;gt;}}&lt;br /&gt;
[[File:Cornucopia_-_Ecommerce_Website_C_Q.png|frame|right]]&lt;br /&gt;
'''Suit:''' [[Cornucopia_-_Ecommerce_Website_-_C|Cornucopia]]&lt;br /&gt;
&lt;br /&gt;
'''Card/Value:''' Q&lt;br /&gt;
&lt;br /&gt;
=== Description: ===&lt;br /&gt;
&lt;br /&gt;
Jim can undertake malicious, non-normal, actions without real-time detection and response by the application.&lt;br /&gt;
&lt;br /&gt;
=== Technical Note: ===&lt;br /&gt;
&lt;br /&gt;
Consider guidance provided by [[OWASP_AppSensor_Project|OWASP AppSensor real-time application level intrusion detection and response]].&lt;br /&gt;
&lt;br /&gt;
=== References: ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;table class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center;&amp;quot;&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;OWASP SCP&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;OWASP ASVS&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;OWASP AppSensor&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;CAPEC&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;SAFECODE&amp;lt;/th&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Application_Security_Verification_Standard#4.17|4.17]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[AppSensor_DetectionPoints|(All)]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[https://capec.mitre.org/ (All)]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[SAFECode_Practical_Security_Stories#1|1]]&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Application_Security_Verification_Standard#15.6|15.6]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[SAFECode_Practical_Security_Stories#27|27]]&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Application_Security_Verification_Standard#15.10|15.10]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;padding:5px;background:LightGray;color:White;font-weight:bold;&amp;quot;&amp;gt;[[Cornucopia_-_Ecommerce_Website_-_C_J|« Previous Card]] &amp;lt;span style=&amp;quot;padding-left:10px;padding-right:10px;&amp;quot;&amp;gt;|&amp;lt;/span&amp;gt;  [[Cornucopia_-_Ecommerce_Website_-_C|Cornucopia]] &amp;lt;span style=&amp;quot;padding-left:10px;padding-right:10px;&amp;quot;&amp;gt;|&amp;lt;/span&amp;gt; [[Cornucopia_-_Ecommerce_Website_-_C_K|Next Card »]] &amp;lt;/div&amp;gt;&lt;/div&gt;</summary>
		<author><name>Dariodf</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cornucopia_-_Ecommerce_Website_-_C_6&amp;diff=207219</id>
		<title>Cornucopia - Ecommerce Website - C 6</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cornucopia_-_Ecommerce_Website_-_C_6&amp;diff=207219"/>
				<updated>2016-01-21T16:30:18Z</updated>
		
		<summary type="html">&lt;p&gt;Dariodf: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{DISPLAYTITLE:&amp;lt;span style=&amp;quot;padding:2px 5px 0px 5px;color:white;background:#17365d;&amp;quot;&amp;gt;Cornucopia - Ecommerce Website - C 6&amp;lt;/span&amp;gt;}}&lt;br /&gt;
[[File:Cornucopia_-_Ecommerce_Website_C_6.png|frame|right]]&lt;br /&gt;
'''Suit:''' [[Cornucopia_-_Ecommerce_Website_-_C|Cornucopia]]&lt;br /&gt;
&lt;br /&gt;
'''Card/Value:''' 6&lt;br /&gt;
&lt;br /&gt;
=== Description: ===&lt;br /&gt;
&lt;br /&gt;
Aaron can bypass controls because error/exception handling is missing, or is implemented inconsistently or partially, or does not deny access by default (i.e. errors should terminate access/execution), or relies on handling by some other service or system.&lt;br /&gt;
&lt;br /&gt;
=== Technical Note: ===&lt;br /&gt;
&lt;br /&gt;
Ensure all forms of error are handled robustly and consistently (e.g. web server, application server, database server, JavaScript, other interpreters). This encompasses:&lt;br /&gt;
* Implement generic error messages and use custom error pages.&lt;br /&gt;
* The application should handle application errors and not rely on the server configuration.&lt;br /&gt;
* Properly free allocated memory when error conditions occur.&lt;br /&gt;
* Error handling logic associated with security controls should deny access by default.&lt;br /&gt;
* When exceptions occur, fail securely.&lt;br /&gt;
&lt;br /&gt;
=== References: ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;table class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center;&amp;quot;&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;OWASP SCP&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;OWASP ASVS&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;OWASP AppSensor&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;CAPEC&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;SAFECODE&amp;lt;/th&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#109|109]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Application_Security_Verification_Standard#8.4|8.4]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[https://capec.mitre.org/data/definitions/54.html 54]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[SAFECode_Practical_Security_Stories#4|4]]&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#110|110]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[https://capec.mitre.org/data/definitions/98.html 98]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[SAFECode_Practical_Security_Stories#11|11]]&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#111|111]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[https://capec.mitre.org/data/definitions/164.html 164]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[SAFECode_Practical_Security_Stories#23|23]]&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#112|112]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#155|155]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;padding:5px;background:LightGray;color:White;font-weight:bold;&amp;quot;&amp;gt;[[Cornucopia_-_Ecommerce_Website_-_C_5|« Previous Card]] &amp;lt;span style=&amp;quot;padding-left:10px;padding-right:10px;&amp;quot;&amp;gt;|&amp;lt;/span&amp;gt;  [[Cornucopia_-_Ecommerce_Website_-_C|Cornucopia]] &amp;lt;span style=&amp;quot;padding-left:10px;padding-right:10px;&amp;quot;&amp;gt;|&amp;lt;/span&amp;gt; [[Cornucopia_-_Ecommerce_Website_-_C_7|Next Card »]] &amp;lt;/div&amp;gt;&lt;/div&gt;</summary>
		<author><name>Dariodf</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cornucopia_-_Ecommerce_Website_-_C_5&amp;diff=207218</id>
		<title>Cornucopia - Ecommerce Website - C 5</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cornucopia_-_Ecommerce_Website_-_C_5&amp;diff=207218"/>
				<updated>2016-01-21T16:30:02Z</updated>
		
		<summary type="html">&lt;p&gt;Dariodf: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{DISPLAYTITLE:&amp;lt;span style=&amp;quot;padding:2px 5px 0px 5px;color:white;background:#17365d;&amp;quot;&amp;gt;Cornucopia - Ecommerce Website - C 5&amp;lt;/span&amp;gt;}}&lt;br /&gt;
[[File:Cornucopia_-_Ecommerce_Website_C_5.png|frame|right]]&lt;br /&gt;
'''Suit:''' [[Cornucopia_-_Ecommerce_Website_-_C|Cornucopia]]&lt;br /&gt;
&lt;br /&gt;
'''Card/Value:''' 5&lt;br /&gt;
&lt;br /&gt;
=== Description: ===&lt;br /&gt;
&lt;br /&gt;
Larry can influence the trust other parties including users have in the application, or abuse that trust elsewhere (e.g. in another application).&lt;br /&gt;
&lt;br /&gt;
=== Technical Note: ===&lt;br /&gt;
&lt;br /&gt;
Abuse of trust attacks include:&lt;br /&gt;
* Clickjacking.&lt;br /&gt;
* Phishing.&lt;br /&gt;
* Pharming.&lt;br /&gt;
* SSL downgrade/misconfiguration.&lt;br /&gt;
&lt;br /&gt;
=== References: ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;table class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center;&amp;quot;&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;OWASP SCP&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;OWASP ASVS&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;OWASP AppSensor&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;CAPEC&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;SAFECODE&amp;lt;/th&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[https://capec.mitre.org/data/definitions/89.html 89]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[https://capec.mitre.org/data/definitions/103.html 103]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[https://capec.mitre.org/data/definitions/181.html 181]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[https://capec.mitre.org/data/definitions/459.html 459]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;padding:5px;background:LightGray;color:White;font-weight:bold;&amp;quot;&amp;gt;[[Cornucopia_-_Ecommerce_Website_-_C_4|« Previous Card]] &amp;lt;span style=&amp;quot;padding-left:10px;padding-right:10px;&amp;quot;&amp;gt;|&amp;lt;/span&amp;gt;  [[Cornucopia_-_Ecommerce_Website_-_C|Cornucopia]] &amp;lt;span style=&amp;quot;padding-left:10px;padding-right:10px;&amp;quot;&amp;gt;|&amp;lt;/span&amp;gt; [[Cornucopia_-_Ecommerce_Website_-_C_6|Next Card »]] &amp;lt;/div&amp;gt;&lt;/div&gt;</summary>
		<author><name>Dariodf</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cornucopia_-_Ecommerce_Website_-_C_3&amp;diff=207217</id>
		<title>Cornucopia - Ecommerce Website - C 3</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cornucopia_-_Ecommerce_Website_-_C_3&amp;diff=207217"/>
				<updated>2016-01-21T16:29:42Z</updated>
		
		<summary type="html">&lt;p&gt;Dariodf: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{DISPLAYTITLE:&amp;lt;span style=&amp;quot;padding:2px 5px 0px 5px;color:white;background:#17365d;&amp;quot;&amp;gt;Cornucopia - Ecommerce Website - C 3&amp;lt;/span&amp;gt;}}&lt;br /&gt;
[[File:Cornucopia_-_Ecommerce_Website_C_3.png|frame|right]]&lt;br /&gt;
'''Suit:''' [[Cornucopia_-_Ecommerce_Website_-_C|Cornucopia]]&lt;br /&gt;
&lt;br /&gt;
'''Card/Value:''' 3&lt;br /&gt;
&lt;br /&gt;
=== Description: ===&lt;br /&gt;
&lt;br /&gt;
Andrew can access source code, or decompile, or otherwise access business logic to understand how the application works and any secrets contained.&lt;br /&gt;
&lt;br /&gt;
=== Technical Note: ===&lt;br /&gt;
&lt;br /&gt;
Protect source code repositories and server-side source-code. Consider anti reverse-engineering techniques. Do not include or minimise logic/secrets within code accessible by users.&lt;br /&gt;
&lt;br /&gt;
=== References: ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;table class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center;&amp;quot;&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;OWASP SCP&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;OWASP ASVS&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;OWASP AppSensor&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;CAPEC&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;SAFECODE&amp;lt;/th&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#134|134]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[https://capec.mitre.org/data/definitions/56.html 56]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[https://capec.mitre.org/data/definitions/189.html 189]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[https://capec.mitre.org/data/definitions/207.html 207]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[https://capec.mitre.org/data/definitions/211.html 211]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;padding:5px;background:LightGray;color:White;font-weight:bold;&amp;quot;&amp;gt;[[Cornucopia_-_Ecommerce_Website_-_C_2|« Previous Card]] &amp;lt;span style=&amp;quot;padding-left:10px;padding-right:10px;&amp;quot;&amp;gt;|&amp;lt;/span&amp;gt;  [[Cornucopia_-_Ecommerce_Website_-_C|Cornucopia]] &amp;lt;span style=&amp;quot;padding-left:10px;padding-right:10px;&amp;quot;&amp;gt;|&amp;lt;/span&amp;gt; [[Cornucopia_-_Ecommerce_Website_-_C_4|Next Card »]] &amp;lt;/div&amp;gt;&lt;/div&gt;</summary>
		<author><name>Dariodf</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cornucopia_-_Ecommerce_Website_-_CR_A&amp;diff=207216</id>
		<title>Cornucopia - Ecommerce Website - CR A</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cornucopia_-_Ecommerce_Website_-_CR_A&amp;diff=207216"/>
				<updated>2016-01-21T16:29:25Z</updated>
		
		<summary type="html">&lt;p&gt;Dariodf: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{DISPLAYTITLE:&amp;lt;span style=&amp;quot;padding:2px 5px 0px 5px;color:white;background:#a395ca;&amp;quot;&amp;gt;Cornucopia - Ecommerce Website - CR A&amp;lt;/span&amp;gt;}}&lt;br /&gt;
[[File:Cornucopia_-_Ecommerce_Website_CR_A.png|frame|right]]&lt;br /&gt;
'''Suit:''' [[Cornucopia_-_Ecommerce_Website_-_CR|Cryptography]]&lt;br /&gt;
&lt;br /&gt;
'''Card/Value:''' A&lt;br /&gt;
&lt;br /&gt;
=== Description: ===&lt;br /&gt;
&lt;br /&gt;
You have invented a new attack against Cryptography.&lt;br /&gt;
&lt;br /&gt;
=== Technical Note: ===&lt;br /&gt;
&lt;br /&gt;
Players can discuss any type of Cryptography (CR) attack they think might be possible against the assessment target. It does not matter if the attack relates to another [[Cornucopia_-_Ecommerce_Website_-_CR|CR]] card, but if possible try to identify an attack that is fairly unique to the application/functionality/users.&lt;br /&gt;
&lt;br /&gt;
=== References: ===&lt;br /&gt;
&lt;br /&gt;
Read more about this topic in OWASP’s free Cheat Sheets on Cryptographic Storage, and Transport Layer Protection.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;padding:5px;background:LightGray;color:White;font-weight:bold;&amp;quot;&amp;gt;[[Cornucopia_-_Ecommerce_Website_-_CR_K|« Previous Card]] &amp;lt;span style=&amp;quot;padding-left:10px;padding-right:10px;&amp;quot;&amp;gt;|&amp;lt;/span&amp;gt;  [[Cornucopia_-_Ecommerce_Website_-_CR|Cryptography]] &amp;lt;span style=&amp;quot;padding-left:10px;padding-right:10px;&amp;quot;&amp;gt;|&amp;lt;/span&amp;gt; [[Cornucopia_-_Ecommerce_Website_-_C_2|Next Card »]] &amp;lt;/div&amp;gt;&lt;/div&gt;</summary>
		<author><name>Dariodf</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cornucopia_-_Ecommerce_Website_-_CR_K&amp;diff=207215</id>
		<title>Cornucopia - Ecommerce Website - CR K</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cornucopia_-_Ecommerce_Website_-_CR_K&amp;diff=207215"/>
				<updated>2016-01-21T16:29:13Z</updated>
		
		<summary type="html">&lt;p&gt;Dariodf: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{DISPLAYTITLE:&amp;lt;span style=&amp;quot;padding:2px 5px 0px 5px;color:white;background:#a395ca;&amp;quot;&amp;gt;Cornucopia - Ecommerce Website - CR K&amp;lt;/span&amp;gt;}}&lt;br /&gt;
[[File:Cornucopia_-_Ecommerce_Website_CR_K.png|frame|right]]&lt;br /&gt;
'''Suit:''' [[Cornucopia_-_Ecommerce_Website_-_CR|Cryptography]]&lt;br /&gt;
&lt;br /&gt;
'''Card/Value:''' K&lt;br /&gt;
&lt;br /&gt;
=== Description: ===&lt;br /&gt;
&lt;br /&gt;
Dan can influence or alter cryptography code/routines (encryption, hashing, digital signatures, random number and GUID generation) and can therefore bypass them.&lt;br /&gt;
&lt;br /&gt;
=== Technical Note: ===&lt;br /&gt;
&lt;br /&gt;
In general, all cryptographic routines should be on the server-side using robust, tested and protected routines.&lt;br /&gt;
&lt;br /&gt;
NB: Unlike other cards in this suit, this CR K relates to an attacker being able to change the executing code. This may be due to inadequate source code control, deployment controls or server protection, but could also be modification of client-side code.&lt;br /&gt;
&lt;br /&gt;
=== References: ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;table class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center;&amp;quot;&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;OWASP SCP&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;OWASP ASVS&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;OWASP AppSensor&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;CAPEC&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;SAFECODE&amp;lt;/th&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#31|31]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Application_Security_Verification_Standard#7.1|7.1]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[https://capec.mitre.org/data/definitions/207.html 207]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[SAFECode_Practical_Security_Stories#14|14]]&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#101|101]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[https://capec.mitre.org/data/definitions/211.html 211]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[SAFECode_Practical_Security_Stories#21|21]]&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[SAFECode_Practical_Security_Stories#29|29]]&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;padding:5px;background:LightGray;color:White;font-weight:bold;&amp;quot;&amp;gt;[[Cornucopia_-_Ecommerce_Website_-_CR_Q|« Previous Card]] &amp;lt;span style=&amp;quot;padding-left:10px;padding-right:10px;&amp;quot;&amp;gt;|&amp;lt;/span&amp;gt;  [[Cornucopia_-_Ecommerce_Website_-_CR|Cryptography]] &amp;lt;span style=&amp;quot;padding-left:10px;padding-right:10px;&amp;quot;&amp;gt;|&amp;lt;/span&amp;gt; [[Cornucopia_-_Ecommerce_Website_-_CR_A|Next Card »]] &amp;lt;/div&amp;gt;&lt;/div&gt;</summary>
		<author><name>Dariodf</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cornucopia_-_Ecommerce_Website_-_CR_Q&amp;diff=207214</id>
		<title>Cornucopia - Ecommerce Website - CR Q</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cornucopia_-_Ecommerce_Website_-_CR_Q&amp;diff=207214"/>
				<updated>2016-01-21T16:28:57Z</updated>
		
		<summary type="html">&lt;p&gt;Dariodf: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{DISPLAYTITLE:&amp;lt;span style=&amp;quot;padding:2px 5px 0px 5px;color:white;background:#a395ca;&amp;quot;&amp;gt;Cornucopia - Ecommerce Website - CR Q&amp;lt;/span&amp;gt;}}&lt;br /&gt;
[[File:Cornucopia_-_Ecommerce_Website_CR_Q.png|frame|right]]&lt;br /&gt;
'''Suit:''' [[Cornucopia_-_Ecommerce_Website_-_CR|Cryptography]]&lt;br /&gt;
&lt;br /&gt;
'''Card/Value:''' Q&lt;br /&gt;
&lt;br /&gt;
=== Description: ===&lt;br /&gt;
&lt;br /&gt;
Randolph can access or predict the master cryptographic secrets.&lt;br /&gt;
&lt;br /&gt;
=== Technical Note: ===&lt;br /&gt;
&lt;br /&gt;
NB: The key concept for this card is '''protection of master cryptographic secrets''', within the application and more widely in management processes.&lt;br /&gt;
&lt;br /&gt;
=== References: ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;table class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center;&amp;quot;&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;OWASP SCP&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;OWASP ASVS&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;OWASP AppSensor&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;CAPEC&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;SAFECODE&amp;lt;/th&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#35|35]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Application_Security_Verification_Standard#7.3|7.3]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[https://capec.mitre.org/data/definitions/116.html 116]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[SAFECode_Practical_Security_Stories#21|21]]&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#102|102]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[https://capec.mitre.org/data/definitions/117.html 117]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[SAFECode_Practical_Security_Stories#29|29]]&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;padding:5px;background:LightGray;color:White;font-weight:bold;&amp;quot;&amp;gt;[[Cornucopia_-_Ecommerce_Website_-_CR_J|« Previous Card]] &amp;lt;span style=&amp;quot;padding-left:10px;padding-right:10px;&amp;quot;&amp;gt;|&amp;lt;/span&amp;gt;  [[Cornucopia_-_Ecommerce_Website_-_CR|Cryptography]] &amp;lt;span style=&amp;quot;padding-left:10px;padding-right:10px;&amp;quot;&amp;gt;|&amp;lt;/span&amp;gt; [[Cornucopia_-_Ecommerce_Website_-_CR_K|Next Card »]] &amp;lt;/div&amp;gt;&lt;/div&gt;</summary>
		<author><name>Dariodf</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cornucopia_-_Ecommerce_Website_-_CR_J&amp;diff=207213</id>
		<title>Cornucopia - Ecommerce Website - CR J</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cornucopia_-_Ecommerce_Website_-_CR_J&amp;diff=207213"/>
				<updated>2016-01-21T16:28:44Z</updated>
		
		<summary type="html">&lt;p&gt;Dariodf: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{DISPLAYTITLE:&amp;lt;span style=&amp;quot;padding:2px 5px 0px 5px;color:white;background:#a395ca;&amp;quot;&amp;gt;Cornucopia - Ecommerce Website - CR J&amp;lt;/span&amp;gt;}}&lt;br /&gt;
[[File:Cornucopia_-_Ecommerce_Website_CR_J.png|frame|right]]&lt;br /&gt;
'''Suit:''' [[Cornucopia_-_Ecommerce_Website_-_CR|Cryptography]]&lt;br /&gt;
&lt;br /&gt;
'''Card/Value:''' J&lt;br /&gt;
&lt;br /&gt;
=== Description: ===&lt;br /&gt;
&lt;br /&gt;
Justin can read credentials for accessing internal or external resources, services and others systems because they are stored in an unencrypted format, or saved in the source code.&lt;br /&gt;
&lt;br /&gt;
=== Technical Note: ===&lt;br /&gt;
&lt;br /&gt;
NB: The key concept for this card is '''unencrypted storage of account credentials'''.&lt;br /&gt;
&lt;br /&gt;
=== References: ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;table class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center;&amp;quot;&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;OWASP SCP&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;OWASP ASVS&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;OWASP AppSensor&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;CAPEC&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;SAFECODE&amp;lt;/th&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#35|35]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[https://capec.mitre.org/data/definitions/116.html 116]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[SAFECode_Practical_Security_Stories#21|21]]&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#90|90]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[SAFECode_Practical_Security_Stories#29|29]]&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#171|171]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#172|172]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;padding:5px;background:LightGray;color:White;font-weight:bold;&amp;quot;&amp;gt;[[Cornucopia_-_Ecommerce_Website_-_CR_10|« Previous Card]] &amp;lt;span style=&amp;quot;padding-left:10px;padding-right:10px;&amp;quot;&amp;gt;|&amp;lt;/span&amp;gt;  [[Cornucopia_-_Ecommerce_Website_-_CR|Cryptography]] &amp;lt;span style=&amp;quot;padding-left:10px;padding-right:10px;&amp;quot;&amp;gt;|&amp;lt;/span&amp;gt; [[Cornucopia_-_Ecommerce_Website_-_CR_Q|Next Card »]] &amp;lt;/div&amp;gt;&lt;/div&gt;</summary>
		<author><name>Dariodf</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cornucopia_-_Ecommerce_Website_-_CR_9&amp;diff=207212</id>
		<title>Cornucopia - Ecommerce Website - CR 9</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cornucopia_-_Ecommerce_Website_-_CR_9&amp;diff=207212"/>
				<updated>2016-01-21T16:28:25Z</updated>
		
		<summary type="html">&lt;p&gt;Dariodf: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{DISPLAYTITLE:&amp;lt;span style=&amp;quot;padding:2px 5px 0px 5px;color:white;background:#a395ca;&amp;quot;&amp;gt;Cornucopia - Ecommerce Website - CR 9&amp;lt;/span&amp;gt;}}&lt;br /&gt;
[[File:Cornucopia_-_Ecommerce_Website_CR_9.png|frame|right]]&lt;br /&gt;
'''Suit:''' [[Cornucopia_-_Ecommerce_Website_-_CR|Cryptography]]&lt;br /&gt;
&lt;br /&gt;
'''Card/Value:''' 9&lt;br /&gt;
&lt;br /&gt;
=== Description: ===&lt;br /&gt;
&lt;br /&gt;
Andy can bypass random number generation, random GUID generation, hashing and encryption functions because they have been self-built and/or are weak.&lt;br /&gt;
&lt;br /&gt;
=== Technical Note: ===&lt;br /&gt;
&lt;br /&gt;
NB: The key concept for this card is '''use of weak algorithms/functions''', especially self-built ones.&lt;br /&gt;
&lt;br /&gt;
=== References: ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;table class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center;&amp;quot;&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;OWASP SCP&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;OWASP ASVS&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;OWASP AppSensor&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;CAPEC&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;SAFECODE&amp;lt;/th&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#60|60]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Application_Security_Verification_Standard#7.6|7.6]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[https://capec.mitre.org/data/definitions/97.html 97]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[SAFECode_Practical_Security_Stories#14|14]]&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#104|104]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Application_Security_Verification_Standard#7.7|7.7]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[SAFECode_Practical_Security_Stories#21|21]]&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#105|105]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Application_Security_Verification_Standard#7.8|7.8]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[SAFECode_Practical_Security_Stories#29|29]]&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[SAFECode_Practical_Security_Stories#32|32]]&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[SAFECode_Practical_Security_Stories#33|33]]&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;padding:5px;background:LightGray;color:White;font-weight:bold;&amp;quot;&amp;gt;[[Cornucopia_-_Ecommerce_Website_-_CR_8|« Previous Card]] &amp;lt;span style=&amp;quot;padding-left:10px;padding-right:10px;&amp;quot;&amp;gt;|&amp;lt;/span&amp;gt;  [[Cornucopia_-_Ecommerce_Website_-_CR|Cryptography]] &amp;lt;span style=&amp;quot;padding-left:10px;padding-right:10px;&amp;quot;&amp;gt;|&amp;lt;/span&amp;gt; [[Cornucopia_-_Ecommerce_Website_-_CR_10|Next Card »]] &amp;lt;/div&amp;gt;&lt;/div&gt;</summary>
		<author><name>Dariodf</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cornucopia_-_Ecommerce_Website_-_CR_8&amp;diff=207211</id>
		<title>Cornucopia - Ecommerce Website - CR 8</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cornucopia_-_Ecommerce_Website_-_CR_8&amp;diff=207211"/>
				<updated>2016-01-21T16:28:14Z</updated>
		
		<summary type="html">&lt;p&gt;Dariodf: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{DISPLAYTITLE:&amp;lt;span style=&amp;quot;padding:2px 5px 0px 5px;color:white;background:#a395ca;&amp;quot;&amp;gt;Cornucopia - Ecommerce Website - CR 8&amp;lt;/span&amp;gt;}}&lt;br /&gt;
[[File:Cornucopia_-_Ecommerce_Website_CR_8.png|frame|right]]&lt;br /&gt;
'''Suit:''' [[Cornucopia_-_Ecommerce_Website_-_CR|Cryptography]]&lt;br /&gt;
&lt;br /&gt;
'''Card/Value:''' 8&lt;br /&gt;
&lt;br /&gt;
=== Description: ===&lt;br /&gt;
&lt;br /&gt;
Eoin can access stored business data (e.g. passwords, session identifiers, PII, cardholder data) because it is not securely encrypted or securely hashed.&lt;br /&gt;
&lt;br /&gt;
=== Technical Note: ===&lt;br /&gt;
&lt;br /&gt;
NB: The key concept for this card is '''protection of stored data'''.&lt;br /&gt;
&lt;br /&gt;
=== References: ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;table class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center;&amp;quot;&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;OWASP SCP&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;OWASP ASVS&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;OWASP AppSensor&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;CAPEC&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;SAFECODE&amp;lt;/th&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#30|30]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Application_Security_Verification_Standard#2.13|2.13]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[https://capec.mitre.org/data/definitions/31.html 31]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[SAFECode_Practical_Security_Stories#21|21]]&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#31|31]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Application_Security_Verification_Standard#7.7|7.7]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[https://capec.mitre.org/data/definitions/37.html 37]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[SAFECode_Practical_Security_Stories#29|29]]&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#70|70]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Application_Security_Verification_Standard#7.8|7.8]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[https://capec.mitre.org/data/definitions/55.html 55]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[SAFECode_Practical_Security_Stories#31|31]]&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#133|133]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Application_Security_Verification_Standard#8.10|8.10]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#135|135]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Application_Security_Verification_Standard#9.2|9.2]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;padding:5px;background:LightGray;color:White;font-weight:bold;&amp;quot;&amp;gt;[[Cornucopia_-_Ecommerce_Website_-_CR_7|« Previous Card]] &amp;lt;span style=&amp;quot;padding-left:10px;padding-right:10px;&amp;quot;&amp;gt;|&amp;lt;/span&amp;gt;  [[Cornucopia_-_Ecommerce_Website_-_CR|Cryptography]] &amp;lt;span style=&amp;quot;padding-left:10px;padding-right:10px;&amp;quot;&amp;gt;|&amp;lt;/span&amp;gt; [[Cornucopia_-_Ecommerce_Website_-_CR_9|Next Card »]] &amp;lt;/div&amp;gt;&lt;/div&gt;</summary>
		<author><name>Dariodf</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cornucopia_-_Ecommerce_Website_-_CR_6&amp;diff=207210</id>
		<title>Cornucopia - Ecommerce Website - CR 6</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cornucopia_-_Ecommerce_Website_-_CR_6&amp;diff=207210"/>
				<updated>2016-01-21T16:27:55Z</updated>
		
		<summary type="html">&lt;p&gt;Dariodf: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{DISPLAYTITLE:&amp;lt;span style=&amp;quot;padding:2px 5px 0px 5px;color:white;background:#a395ca;&amp;quot;&amp;gt;Cornucopia - Ecommerce Website - CR 6&amp;lt;/span&amp;gt;}}&lt;br /&gt;
[[File:Cornucopia_-_Ecommerce_Website_CR_6.png|frame|right]]&lt;br /&gt;
'''Suit:''' [[Cornucopia_-_Ecommerce_Website_-_CR|Cryptography]]&lt;br /&gt;
&lt;br /&gt;
'''Card/Value:''' 6&lt;br /&gt;
&lt;br /&gt;
=== Description: ===&lt;br /&gt;
&lt;br /&gt;
Romain can read and modify data in memory or in transit (e.g. cryptographic secrets, credentials, session identifiers, personal and commercially-sensitive data), in use or in communications within the application, or between the application and users, or between the application and external systems.&lt;br /&gt;
&lt;br /&gt;
=== Technical Note: ===&lt;br /&gt;
&lt;br /&gt;
NB: The key concept for this card is '''lack of encryption''' of data '''in transit''' and/or '''in memory'''.&lt;br /&gt;
&lt;br /&gt;
=== References: ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;table class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center;&amp;quot;&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;OWASP SCP&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;OWASP ASVS&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;OWASP AppSensor&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;CAPEC&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;SAFECODE&amp;lt;/th&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#36|36]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Application_Security_Verification_Standard#9.2|9.2]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[https://capec.mitre.org/data/definitions/31.html 31]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[SAFECode_Practical_Security_Stories#29|29]]&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#37|37]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Application_Security_Verification_Standard#10.2|10.2]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[https://capec.mitre.org/data/definitions/57.html 57]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#143|143]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Application_Security_Verification_Standard#10.3|10.3]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[https://capec.mitre.org/data/definitions/102.html 102]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#146|146]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Application_Security_Verification_Standard#10.7|10.7]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[https://capec.mitre.org/data/definitions/158.html 158]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#147|147]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[https://capec.mitre.org/data/definitions/384.html 384]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[https://capec.mitre.org/data/definitions/466.html 466]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;padding:5px;background:LightGray;color:White;font-weight:bold;&amp;quot;&amp;gt;[[Cornucopia_-_Ecommerce_Website_-_CR_5|« Previous Card]] &amp;lt;span style=&amp;quot;padding-left:10px;padding-right:10px;&amp;quot;&amp;gt;|&amp;lt;/span&amp;gt;  [[Cornucopia_-_Ecommerce_Website_-_CR|Cryptography]] &amp;lt;span style=&amp;quot;padding-left:10px;padding-right:10px;&amp;quot;&amp;gt;|&amp;lt;/span&amp;gt; [[Cornucopia_-_Ecommerce_Website_-_CR_7|Next Card »]] &amp;lt;/div&amp;gt;&lt;/div&gt;</summary>
		<author><name>Dariodf</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cornucopia_-_Ecommerce_Website_-_CR_5&amp;diff=207209</id>
		<title>Cornucopia - Ecommerce Website - CR 5</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cornucopia_-_Ecommerce_Website_-_CR_5&amp;diff=207209"/>
				<updated>2016-01-21T16:27:42Z</updated>
		
		<summary type="html">&lt;p&gt;Dariodf: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{DISPLAYTITLE:&amp;lt;span style=&amp;quot;padding:2px 5px 0px 5px;color:white;background:#a395ca;&amp;quot;&amp;gt;Cornucopia - Ecommerce Website - CR 5&amp;lt;/span&amp;gt;}}&lt;br /&gt;
[[File:Cornucopia_-_Ecommerce_Website_CR_5.png|frame|right]]&lt;br /&gt;
'''Suit:''' [[Cornucopia_-_Ecommerce_Website_-_CR|Cryptography]]&lt;br /&gt;
&lt;br /&gt;
'''Card/Value:''' 5&lt;br /&gt;
&lt;br /&gt;
=== Description: ===&lt;br /&gt;
&lt;br /&gt;
Kyle can bypass cryptographic controls because they do not fail securely (i.e. they default to unprotected).&lt;br /&gt;
&lt;br /&gt;
=== Technical Note: ===&lt;br /&gt;
&lt;br /&gt;
Crypotographic function errors always need to result in rejection. It is also useful to log (associated with the user's identity if possible) and flag these as possibly malicious activity for further analysis, or as input for application intrusion detection systems.&lt;br /&gt;
&lt;br /&gt;
NB: Unlike [[Cornucopia_-_Ecommerce_Website_-_CR|other cards in this suit]], CR 5 assumes that cryptographic functions are in place, however they do not correctly respond to errors.&lt;br /&gt;
&lt;br /&gt;
=== References: ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;table class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center;&amp;quot;&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;OWASP SCP&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;OWASP ASVS&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;OWASP AppSensor&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;CAPEC&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;SAFECODE&amp;lt;/th&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#103|103]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Application_Security_Verification_Standard#7.2|7.2]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[https://capec.mitre.org/data/definitions/97.html 97]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[SAFECode_Practical_Security_Stories#21|21]]&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#145|145]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[SAFECode_Practical_Security_Stories#29|29]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;padding:5px;background:LightGray;color:White;font-weight:bold;&amp;quot;&amp;gt;[[Cornucopia_-_Ecommerce_Website_-_CR_4|« Previous Card]] &amp;lt;span style=&amp;quot;padding-left:10px;padding-right:10px;&amp;quot;&amp;gt;|&amp;lt;/span&amp;gt;  [[Cornucopia_-_Ecommerce_Website_-_CR|Cryptography]] &amp;lt;span style=&amp;quot;padding-left:10px;padding-right:10px;&amp;quot;&amp;gt;|&amp;lt;/span&amp;gt; [[Cornucopia_-_Ecommerce_Website_-_CR_6|Next Card »]] &amp;lt;/div&amp;gt;&lt;/div&gt;</summary>
		<author><name>Dariodf</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cornucopia_-_Ecommerce_Website_-_CR_4&amp;diff=207208</id>
		<title>Cornucopia - Ecommerce Website - CR 4</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cornucopia_-_Ecommerce_Website_-_CR_4&amp;diff=207208"/>
				<updated>2016-01-21T16:27:24Z</updated>
		
		<summary type="html">&lt;p&gt;Dariodf: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{DISPLAYTITLE:&amp;lt;span style=&amp;quot;padding:2px 5px 0px 5px;color:white;background:#a395ca;&amp;quot;&amp;gt;Cornucopia - Ecommerce Website - CR 4&amp;lt;/span&amp;gt;}}&lt;br /&gt;
[[File:Cornucopia_-_Ecommerce_Website_CR_4.png|frame|right]]&lt;br /&gt;
'''Suit:''' [[Cornucopia_-_Ecommerce_Website_-_CR|Cryptography]]&lt;br /&gt;
&lt;br /&gt;
'''Card/Value:''' 4&lt;br /&gt;
&lt;br /&gt;
=== Description: ===&lt;br /&gt;
&lt;br /&gt;
Paulo can access data in transit that is not encrypted, even though the channel is encrypted.&lt;br /&gt;
&lt;br /&gt;
=== Technical Note: ===&lt;br /&gt;
&lt;br /&gt;
Data may be use encryption in transit like Transport Layer Security (TLS). However, an attacker may have legitimate access to this (e.g. viewing SSL content in a web browser). Consider whether the data transmitted also needs to be encrypted itself, not just sent using an encrypted protocol.&lt;br /&gt;
&lt;br /&gt;
=== References: ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;table class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center;&amp;quot;&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;OWASP SCP&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;OWASP ASVS&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;OWASP AppSensor&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;CAPEC&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;SAFECODE&amp;lt;/th&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#37|37]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Application_Security_Verification_Standard#9.2|9.2]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[https://capec.mitre.org/data/definitions/185.html 185]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[SAFECode_Practical_Security_Stories#14|14]]&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#88|88]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[https://capec.mitre.org/data/definitions/186.html 186]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[SAFECode_Practical_Security_Stories#29|29]]&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#143|143]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[https://capec.mitre.org/data/definitions/187.html 187]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[SAFECode_Practical_Security_Stories#30|30]]&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#214|214]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;padding:5px;background:LightGray;color:White;font-weight:bold;&amp;quot;&amp;gt;[[Cornucopia_-_Ecommerce_Website_-_CR_3|« Previous Card]] &amp;lt;span style=&amp;quot;padding-left:10px;padding-right:10px;&amp;quot;&amp;gt;|&amp;lt;/span&amp;gt;  [[Cornucopia_-_Ecommerce_Website_-_CR|Cryptography]] &amp;lt;span style=&amp;quot;padding-left:10px;padding-right:10px;&amp;quot;&amp;gt;|&amp;lt;/span&amp;gt; [[Cornucopia_-_Ecommerce_Website_-_CR_5|Next Card »]] &amp;lt;/div&amp;gt;&lt;/div&gt;</summary>
		<author><name>Dariodf</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cornucopia_-_Ecommerce_Website_-_CR_2&amp;diff=207207</id>
		<title>Cornucopia - Ecommerce Website - CR 2</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cornucopia_-_Ecommerce_Website_-_CR_2&amp;diff=207207"/>
				<updated>2016-01-21T16:27:01Z</updated>
		
		<summary type="html">&lt;p&gt;Dariodf: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{DISPLAYTITLE:&amp;lt;span style=&amp;quot;padding:2px 5px 0px 5px;color:white;background:#a395ca;&amp;quot;&amp;gt;Cornucopia - Ecommerce Website - CR 2&amp;lt;/span&amp;gt;}}&lt;br /&gt;
[[File:Cornucopia_-_Ecommerce_Website_CR_2.png|frame|right]]&lt;br /&gt;
'''Suit:''' [[Cornucopia_-_Ecommerce_Website_-_CR|Cryptography]]&lt;br /&gt;
&lt;br /&gt;
'''Card/Value:''' 2&lt;br /&gt;
&lt;br /&gt;
=== Description: ===&lt;br /&gt;
&lt;br /&gt;
Kyun can access data because it has been obfuscated rather than using an approved cryptographic function.&lt;br /&gt;
&lt;br /&gt;
=== Technical Note: ===&lt;br /&gt;
&lt;br /&gt;
There is no substitute for a proper, approved, cryptographic function where data needs to be protected at rest or in transit. Obfuscation is rarely the correct choice. Use standard-sapproved functions and consider all cryptographic management requirements (e.g. key creation, distribution, protection, replacement, retirement).&lt;br /&gt;
&lt;br /&gt;
=== References: ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;table class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center;&amp;quot;&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;OWASP SCP&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;OWASP ASVS&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;OWASP AppSensor&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;CAPEC&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;SAFECODE&amp;lt;/th&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#105|105]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[SAFECode_Practical_Security_Stories#21|21]]&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#133|133]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[SAFECode_Practical_Security_Stories#29|29]]&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#135|135]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;padding:5px;background:LightGray;color:White;font-weight:bold;&amp;quot;&amp;gt;[[Cornucopia_-_Ecommerce_Website_-_AZ_A|« Previous Card]] &amp;lt;span style=&amp;quot;padding-left:10px;padding-right:10px;&amp;quot;&amp;gt;|&amp;lt;/span&amp;gt;  [[Cornucopia_-_Ecommerce_Website_-_CR|Cryptography]] &amp;lt;span style=&amp;quot;padding-left:10px;padding-right:10px;&amp;quot;&amp;gt;|&amp;lt;/span&amp;gt; [[Cornucopia_-_Ecommerce_Website_-_CR_3|Next Card »]] &amp;lt;/div&amp;gt;&lt;/div&gt;</summary>
		<author><name>Dariodf</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cornucopia_-_Ecommerce_Website_-_AZ_A&amp;diff=207206</id>
		<title>Cornucopia - Ecommerce Website - AZ A</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cornucopia_-_Ecommerce_Website_-_AZ_A&amp;diff=207206"/>
				<updated>2016-01-21T16:26:43Z</updated>
		
		<summary type="html">&lt;p&gt;Dariodf: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{DISPLAYTITLE:&amp;lt;span style=&amp;quot;padding:2px 5px 0px 5px;color:white;background:#d9c049;&amp;quot;&amp;gt;Cornucopia - Ecommerce Website - AZ A&amp;lt;/span&amp;gt;}}&lt;br /&gt;
[[File:Cornucopia_-_Ecommerce_Website_AZ_A.png|frame|right]]&lt;br /&gt;
'''Suit:''' [[Cornucopia_-_Ecommerce_Website_-_AZ|Authorization]]&lt;br /&gt;
&lt;br /&gt;
'''Card/Value:''' A&lt;br /&gt;
&lt;br /&gt;
=== Description: ===&lt;br /&gt;
&lt;br /&gt;
You have invented a new attack against Authorization.&lt;br /&gt;
&lt;br /&gt;
=== Technical Note: ===&lt;br /&gt;
&lt;br /&gt;
Players can discuss any type of Authorization (AZ) attack they think might be possible against the assessment target. It does not matter if the attack relates to another [[Cornucopia_-_Ecommerce_Website_-_AZ|AZ]] card, but if possible try to identify an attack that is fairly unique to the application/functionality/users.&lt;br /&gt;
&lt;br /&gt;
=== References: ===&lt;br /&gt;
&lt;br /&gt;
Read more about this topic in OWASP’s Development and Testing Guides&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;padding:5px;background:LightGray;color:White;font-weight:bold;&amp;quot;&amp;gt;[[Cornucopia_-_Ecommerce_Website_-_AZ_K|« Previous Card]] &amp;lt;span style=&amp;quot;padding-left:10px;padding-right:10px;&amp;quot;&amp;gt;|&amp;lt;/span&amp;gt;  [[Cornucopia_-_Ecommerce_Website_-_AZ|Authorization]] &amp;lt;span style=&amp;quot;padding-left:10px;padding-right:10px;&amp;quot;&amp;gt;|&amp;lt;/span&amp;gt; [[Cornucopia_-_Ecommerce_Website_-_CR_2|Next Card »]] &amp;lt;/div&amp;gt;&lt;/div&gt;</summary>
		<author><name>Dariodf</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cornucopia_-_Ecommerce_Website_-_AZ_K&amp;diff=207205</id>
		<title>Cornucopia - Ecommerce Website - AZ K</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cornucopia_-_Ecommerce_Website_-_AZ_K&amp;diff=207205"/>
				<updated>2016-01-21T16:26:25Z</updated>
		
		<summary type="html">&lt;p&gt;Dariodf: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{DISPLAYTITLE:&amp;lt;span style=&amp;quot;padding:2px 5px 0px 5px;color:white;background:#d9c049;&amp;quot;&amp;gt;Cornucopia - Ecommerce Website - AZ K&amp;lt;/span&amp;gt;}}&lt;br /&gt;
[[File:Cornucopia_-_Ecommerce_Website_AZ_K.png|frame|right]]&lt;br /&gt;
'''Suit:''' [[Cornucopia_-_Ecommerce_Website_-_AZ|Authorization]]&lt;br /&gt;
&lt;br /&gt;
'''Card/Value:''' K&lt;br /&gt;
&lt;br /&gt;
=== Description: ===&lt;br /&gt;
&lt;br /&gt;
Ryan can influence or alter authorization controls and permissions, and can therefore bypass them.&lt;br /&gt;
&lt;br /&gt;
=== Technical Note: ===&lt;br /&gt;
&lt;br /&gt;
Use only trusted system objects, e.g. server side session objects, for making access authorization decisions. Restrict access to user and data attributes and policy information used by access controls. Server side implementation and presentation layer representations of access control rules must match.&lt;br /&gt;
&lt;br /&gt;
=== References: ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;table class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center;&amp;quot;&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;OWASP SCP&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;OWASP ASVS&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;OWASP AppSensor&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;CAPEC&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;SAFECODE&amp;lt;/th&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#77|77]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Application_Security_Verification_Standard#4.9|4.9]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[https://capec.mitre.org/data/definitions/56.html 56]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[SAFECode_Practical_Security_Stories#8|8]]&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#89|89]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Application_Security_Verification_Standard#4.10|4.10]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[https://capec.mitre.org/data/definitions/207.html 207]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[SAFECode_Practical_Security_Stories#10|10]]&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#91|91]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Application_Security_Verification_Standard#4.11|4.11]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[https://capec.mitre.org/data/definitions/211.html 211]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[SAFECode_Practical_Security_Stories#11|11]]&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;padding:5px;background:LightGray;color:White;font-weight:bold;&amp;quot;&amp;gt;[[Cornucopia_-_Ecommerce_Website_-_AZ_Q|« Previous Card]] &amp;lt;span style=&amp;quot;padding-left:10px;padding-right:10px;&amp;quot;&amp;gt;|&amp;lt;/span&amp;gt;  [[Cornucopia_-_Ecommerce_Website_-_AZ|Authorization]] &amp;lt;span style=&amp;quot;padding-left:10px;padding-right:10px;&amp;quot;&amp;gt;|&amp;lt;/span&amp;gt; [[Cornucopia_-_Ecommerce_Website_-_AZ_A|Next Card »]] &amp;lt;/div&amp;gt;&lt;/div&gt;</summary>
		<author><name>Dariodf</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cornucopia_-_Ecommerce_Website_-_AZ_J&amp;diff=207204</id>
		<title>Cornucopia - Ecommerce Website - AZ J</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cornucopia_-_Ecommerce_Website_-_AZ_J&amp;diff=207204"/>
				<updated>2016-01-21T16:26:12Z</updated>
		
		<summary type="html">&lt;p&gt;Dariodf: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{DISPLAYTITLE:&amp;lt;span style=&amp;quot;padding:2px 5px 0px 5px;color:white;background:#d9c049;&amp;quot;&amp;gt;Cornucopia - Ecommerce Website - AZ J&amp;lt;/span&amp;gt;}}&lt;br /&gt;
[[File:Cornucopia_-_Ecommerce_Website_AZ_J.png|frame|right]]&lt;br /&gt;
'''Suit:''' [[Cornucopia_-_Ecommerce_Website_-_AZ|Authorization]]&lt;br /&gt;
&lt;br /&gt;
'''Card/Value:''' J&lt;br /&gt;
&lt;br /&gt;
=== Description: ===&lt;br /&gt;
&lt;br /&gt;
Dinis can access security configuration information, or access control lists.&lt;br /&gt;
&lt;br /&gt;
=== Technical Note: ===&lt;br /&gt;
&lt;br /&gt;
Restrict access security-relevant configuration information to only appropriate authorized users.&lt;br /&gt;
&lt;br /&gt;
=== References: ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;table class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center;&amp;quot;&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;OWASP SCP&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;OWASP ASVS&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;OWASP AppSensor&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;CAPEC&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;SAFECODE&amp;lt;/th&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#89|89]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Application_Security_Verification_Standard#4.10|4.10]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[https://capec.mitre.org/data/definitions/75.html 75]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[SAFECode_Practical_Security_Stories#8|8]]&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#90|90]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Application_Security_Verification_Standard#7.3|7.3]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[https://capec.mitre.org/data/definitions/133.html 133]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[SAFECode_Practical_Security_Stories#10|10]]&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Application_Security_Verification_Standard#13.2|13.2]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[https://capec.mitre.org/data/definitions/203.html 203]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[SAFECode_Practical_Security_Stories#11|11]]&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;padding:5px;background:LightGray;color:White;font-weight:bold;&amp;quot;&amp;gt;[[Cornucopia_-_Ecommerce_Website_-_AZ_10|« Previous Card]] &amp;lt;span style=&amp;quot;padding-left:10px;padding-right:10px;&amp;quot;&amp;gt;|&amp;lt;/span&amp;gt;  [[Cornucopia_-_Ecommerce_Website_-_AZ|Authorization]] &amp;lt;span style=&amp;quot;padding-left:10px;padding-right:10px;&amp;quot;&amp;gt;|&amp;lt;/span&amp;gt; [[Cornucopia_-_Ecommerce_Website_-_AZ_Q|Next Card »]] &amp;lt;/div&amp;gt;&lt;/div&gt;</summary>
		<author><name>Dariodf</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cornucopia_-_Ecommerce_Website_-_AZ_Q&amp;diff=207203</id>
		<title>Cornucopia - Ecommerce Website - AZ Q</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cornucopia_-_Ecommerce_Website_-_AZ_Q&amp;diff=207203"/>
				<updated>2016-01-21T16:26:00Z</updated>
		
		<summary type="html">&lt;p&gt;Dariodf: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{DISPLAYTITLE:&amp;lt;span style=&amp;quot;padding:2px 5px 0px 5px;color:white;background:#d9c049;&amp;quot;&amp;gt;Cornucopia - Ecommerce Website - AZ Q&amp;lt;/span&amp;gt;}}&lt;br /&gt;
[[File:Cornucopia_-_Ecommerce_Website_AZ_Q.png|frame|right]]&lt;br /&gt;
'''Suit:''' [[Cornucopia_-_Ecommerce_Website_-_AZ|Authorization]]&lt;br /&gt;
&lt;br /&gt;
'''Card/Value:''' Q&lt;br /&gt;
&lt;br /&gt;
=== Description: ===&lt;br /&gt;
&lt;br /&gt;
Christopher can inject a command that the application will run at a higher privilege level.&lt;br /&gt;
&lt;br /&gt;
=== Technical Note: ===&lt;br /&gt;
&lt;br /&gt;
Firstly apply appropriate [[Cornucopia_-_Ecommerce_Website_-_VE|input validation and encoding]]. In cases where the application must run with elevated privileges, raise privileges as late as possible, and drop them as soon as possible.&lt;br /&gt;
&lt;br /&gt;
=== References: ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;table class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center;&amp;quot;&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;OWASP SCP&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;OWASP ASVS&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;OWASP AppSensor&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;CAPEC&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;SAFECODE&amp;lt;/th&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#209|209]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Application_Security_Verification_Standard#5.12|5.12]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[https://capec.mitre.org/data/definitions/17.html 17]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[SAFECode_Practical_Security_Stories#8|8]]&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Application_Security_Verification_Standard#15.7|15.7]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[https://capec.mitre.org/data/definitions/30.html 30]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[SAFECode_Practical_Security_Stories#10|10]]&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[https://capec.mitre.org/data/definitions/69.html 69]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[SAFECode_Practical_Security_Stories#11|11]]&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[https://capec.mitre.org/data/definitions/234.html 234]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;padding:5px;background:LightGray;color:White;font-weight:bold;&amp;quot;&amp;gt;[[Cornucopia_-_Ecommerce_Website_-_AZ_J|« Previous Card]] &amp;lt;span style=&amp;quot;padding-left:10px;padding-right:10px;&amp;quot;&amp;gt;|&amp;lt;/span&amp;gt;  [[Cornucopia_-_Ecommerce_Website_-_AZ|Authorization]] &amp;lt;span style=&amp;quot;padding-left:10px;padding-right:10px;&amp;quot;&amp;gt;|&amp;lt;/span&amp;gt; [[Cornucopia_-_Ecommerce_Website_-_AZ_K|Next Card »]] &amp;lt;/div&amp;gt;&lt;/div&gt;</summary>
		<author><name>Dariodf</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cornucopia_-_Ecommerce_Website_-_AZ_J&amp;diff=207202</id>
		<title>Cornucopia - Ecommerce Website - AZ J</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cornucopia_-_Ecommerce_Website_-_AZ_J&amp;diff=207202"/>
				<updated>2016-01-21T16:25:48Z</updated>
		
		<summary type="html">&lt;p&gt;Dariodf: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{DISPLAYTITLE:&amp;lt;span style=&amp;quot;padding:2px 5px 0px 5px;color:white;background:#d9c049;&amp;quot;&amp;gt;Cornucopia - Ecommerce Website - AZ J&amp;lt;/span&amp;gt;}}&lt;br /&gt;
[[File:Cornucopia_-_Ecommerce_Website_AZ_J.png|frame|right]]&lt;br /&gt;
'''Suit:''' [[Cornucopia_-_Ecommerce_Website_-_AZ|Authorization]]&lt;br /&gt;
&lt;br /&gt;
'''Card/Value:''' J&lt;br /&gt;
&lt;br /&gt;
=== Description: ===&lt;br /&gt;
&lt;br /&gt;
Dinis can access security configuration information, or access control lists.&lt;br /&gt;
&lt;br /&gt;
=== Technical Note: ===&lt;br /&gt;
&lt;br /&gt;
Restrict access security-relevant configuration information to only appropriate authorized users.&lt;br /&gt;
&lt;br /&gt;
=== References: ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;table class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center;&amp;quot;&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;OWASP SCP&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;OWASP ASVS&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;OWASP AppSensor&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;CAPEC&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;SAFECODE&amp;lt;/th&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#89|89]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Application_Security_Verification_Standard#4.10|4.10]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[https://capec.mitre.org/data/definitions/75.html 75]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[SAFECode_Practical_Security_Stories#8|8]]&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#90|90]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Application_Security_Verification_Standard#7.3|7.3]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[https://capec.mitre.org/data/definitions/133.html 133]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[SAFECode_Practical_Security_Stories#10|10]]&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Application_Security_Verification_Standard#13.2|13.2]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[https://capec.mitre.org/data/definitions/203.html 203]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[SAFECode_Practical_Security_Stories#11|11]]&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;padding:5px;background:LightGray;color:White;font-weight:bold;&amp;quot;&amp;gt;[[Cornucopia_-_Ecommerce_Website_-_AZ_10|« Previous Card]] &amp;lt;span style=&amp;quot;padding-left:10px;padding-right:10px;&amp;quot;&amp;gt;|&amp;lt;/span&amp;gt;  [[Cornucopia_-_Ecommerce_Website_-_AZ|Authorization]] &amp;lt;span style=&amp;quot;padding-left:10px;padding-right:10px;&amp;quot;&amp;gt;|&amp;lt;/span&amp;gt; [[Cornucopia_-_Ecommerce_Website_-_AZ_Q|Next Card »]] &amp;lt;/div&amp;gt;&lt;/div&gt;</summary>
		<author><name>Dariodf</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cornucopia_-_Ecommerce_Website_-_AZ_J&amp;diff=207201</id>
		<title>Cornucopia - Ecommerce Website - AZ J</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cornucopia_-_Ecommerce_Website_-_AZ_J&amp;diff=207201"/>
				<updated>2016-01-21T16:25:41Z</updated>
		
		<summary type="html">&lt;p&gt;Dariodf: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{DISPLAYTITLE:&amp;lt;span style=&amp;quot;padding:2px 5px 0px 5px;color:white;background:#d9c049;&amp;quot;&amp;gt;Cornucopia - Ecommerce Website - AZ J&amp;lt;/span&amp;gt;}}&lt;br /&gt;
[[File:Cornucopia_-_Ecommerce_Website_AZ_J.png|frame|right]]&lt;br /&gt;
'''Suit:''' [[Cornucopia_-_Ecommerce_Website_-_AZ|Authorization]]&lt;br /&gt;
&lt;br /&gt;
'''Card/Value:''' J&lt;br /&gt;
&lt;br /&gt;
=== Description: ===&lt;br /&gt;
&lt;br /&gt;
Dinis can access security configuration information, or access control lists.&lt;br /&gt;
&lt;br /&gt;
=== Technical Note: ===&lt;br /&gt;
&lt;br /&gt;
Restrict access security-relevant configuration information to only appropriate authorized users.&lt;br /&gt;
&lt;br /&gt;
=== References: ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;table class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center;&amp;quot;&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;OWASP SCP&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;OWASP ASVS&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;OWASP AppSensor&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;CAPEC&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;SAFECODE&amp;lt;/th&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#89|89]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Application_Security_Verification_Standard#4.10|4.10]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[https://capec.mitre.org/data/definitions/75.html 75]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[SAFECode_Practical_Security_Stories#8|8]]&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#90|90]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Application_Security_Verification_Standard#7.3|7.3]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[https://capec.mitre.org/data/definitions/133.html 133]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[SAFECode_Practical_Security_Stories#10|10]]&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Application_Security_Verification_Standard#13.2|13.2]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[https://capec.mitre.org/data/definitions/203.html 203]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[SAFECode_Practical_Security_Stories#11|11]]&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;padding:5px;background:LightGray;color:White;font-weight:bold;&amp;quot;&amp;gt;[[Cornucopia_-_Ecommerce_Website_-_AZ_10|« Previous Card]] &amp;lt;span style=&amp;quot;padding-left:10px;padding-right:10px;&amp;quot;&amp;gt;|&amp;lt;/span&amp;gt;  [[Cornucopia_-_Ecommerce_Website_-_AZ|Authorization]] &amp;lt;span style=&amp;quot;padding-left:10px;padding-right:10px;&amp;quot;&amp;gt;|&amp;lt;/span&amp;gt; [[Cornucopia_-_Ecommerce_Website_-_AZ_Q|Next Card »]] &amp;lt;/div&amp;gt;&lt;/div&gt;</summary>
		<author><name>Dariodf</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cornucopia_-_Ecommerce_Website_-_AZ_10&amp;diff=207200</id>
		<title>Cornucopia - Ecommerce Website - AZ 10</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cornucopia_-_Ecommerce_Website_-_AZ_10&amp;diff=207200"/>
				<updated>2016-01-21T16:25:31Z</updated>
		
		<summary type="html">&lt;p&gt;Dariodf: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{DISPLAYTITLE:&amp;lt;span style=&amp;quot;padding:2px 5px 0px 5px;color:white;background:#d9c049;&amp;quot;&amp;gt;Cornucopia - Ecommerce Website - AZ 10&amp;lt;/span&amp;gt;}}&lt;br /&gt;
[[File:Cornucopia_-_Ecommerce_Website_AZ_10.png|frame|right]]&lt;br /&gt;
'''Suit:''' [[Cornucopia_-_Ecommerce_Website_-_AZ|Authorization]]&lt;br /&gt;
&lt;br /&gt;
'''Card/Value:''' 10&lt;br /&gt;
&lt;br /&gt;
=== Description: ===&lt;br /&gt;
&lt;br /&gt;
Richard can bypass the centralized authorization controls since they are not being used comprehensively on all interactions.&lt;br /&gt;
&lt;br /&gt;
=== Technical Note: ===&lt;br /&gt;
&lt;br /&gt;
Centralized authorization routines are a good programming practice, but like other routines, developers need to understand how they work, how to use them and any limitations. Such routines can be tested independently of other code and not only provide assurance on the quality, but it make refactorization an easy task and eliminate code duplicates and bad interpretations.&lt;br /&gt;
&lt;br /&gt;
Server side implementation and presentation layer representations of access control rules must match.&lt;br /&gt;
&lt;br /&gt;
=== References: ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;table class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center;&amp;quot;&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;OWASP SCP&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;OWASP ASVS&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;OWASP AppSensor&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;CAPEC&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;SAFECODE&amp;lt;/th&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#78|78]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Application_Security_Verification_Standard#4.1|4.1]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[AppSensor_DetectionPoints#ACE1|ACE1]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[https://capec.mitre.org/data/definitions/36.html 36]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[SAFECode_Practical_Security_Stories#8|8]]&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#91|91]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Application_Security_Verification_Standard#4.12|4.12]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[AppSensor_DetectionPoints#ACE2|ACE2]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[https://capec.mitre.org/data/definitions/95.html 95]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[SAFECode_Practical_Security_Stories#10|10]]&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[AppSensor_DetectionPoints#ACE3|ACE3]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[https://capec.mitre.org/data/definitions/121.html 121]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[SAFECode_Practical_Security_Stories#11|11]]&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[AppSensor_DetectionPoints#ACE4|ACE4]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[https://capec.mitre.org/data/definitions/179.html 179]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;padding:5px;background:LightGray;color:White;font-weight:bold;&amp;quot;&amp;gt;[[Cornucopia_-_Ecommerce_Website_-_AZ_9|« Previous Card]] &amp;lt;span style=&amp;quot;padding-left:10px;padding-right:10px;&amp;quot;&amp;gt;|&amp;lt;/span&amp;gt;  [[Cornucopia_-_Ecommerce_Website_-_AZ|Authorization]] &amp;lt;span style=&amp;quot;padding-left:10px;padding-right:10px;&amp;quot;&amp;gt;|&amp;lt;/span&amp;gt; [[Cornucopia_-_Ecommerce_Website_-_AZ_J|Next Card »]] &amp;lt;/div&amp;gt;&lt;/div&gt;</summary>
		<author><name>Dariodf</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cornucopia_-_Ecommerce_Website_-_AZ_7&amp;diff=207199</id>
		<title>Cornucopia - Ecommerce Website - AZ 7</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cornucopia_-_Ecommerce_Website_-_AZ_7&amp;diff=207199"/>
				<updated>2016-01-21T16:24:38Z</updated>
		
		<summary type="html">&lt;p&gt;Dariodf: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{DISPLAYTITLE:&amp;lt;span style=&amp;quot;padding:2px 5px 0px 5px;color:white;background:#d9c049;&amp;quot;&amp;gt;Cornucopia - Ecommerce Website - AZ 7&amp;lt;/span&amp;gt;}}&lt;br /&gt;
[[File:Cornucopia_-_Ecommerce_Website_AZ_7.png|frame|right]]&lt;br /&gt;
'''Suit:''' [[Cornucopia_-_Ecommerce_Website_-_AZ|Authorization]]&lt;br /&gt;
&lt;br /&gt;
'''Card/Value:''' 7&lt;br /&gt;
&lt;br /&gt;
=== Description: ===&lt;br /&gt;
&lt;br /&gt;
Yuanjing can access application functions, objects, or properties he is not authorized to access.&lt;br /&gt;
&lt;br /&gt;
=== Technical Note: ===&lt;br /&gt;
&lt;br /&gt;
Implement least privilege, and restrict users to only the functionality, objects and properties that are required to perform their tasks.&lt;br /&gt;
&lt;br /&gt;
NB: the key concept for this card is applying function/object/property authorization controls. See [[Cornucopia_-_Ecommerce_Website_-_AZ_5|AZ 5]] for resource type controls, and [[Cornucopia_-_Ecommerce_Website_-_AZ_6|AZ 6]] for data controls.&lt;br /&gt;
&lt;br /&gt;
=== References: ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;table class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center;&amp;quot;&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;OWASP SCP&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;OWASP ASVS&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;OWASP AppSensor&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;CAPEC&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;SAFECODE&amp;lt;/th&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#81|81]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Application_Security_Verification_Standard#4.1|4.1]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[AppSensor_DetectionPoints#ACE1|ACE1]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[https://capec.mitre.org/data/definitions/122.html 122]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[SAFECode_Practical_Security_Stories#8|8]]&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#85|85]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Application_Security_Verification_Standard#4.2|4.2]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[AppSensor_DetectionPoints#ACE2|ACE2]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[SAFECode_Practical_Security_Stories#10|10]]&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#86|86]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Application_Security_Verification_Standard#4.3|4.3]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[AppSensor_DetectionPoints#ACE3|ACE3]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[SAFECode_Practical_Security_Stories#11|11]]&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#131|131]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Application_Security_Verification_Standard#4.4|4.4]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[AppSensor_DetectionPoints#ACE4|ACE4]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Application_Security_Verification_Standard#15.7|15.7]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;padding:5px;background:LightGray;color:White;font-weight:bold;&amp;quot;&amp;gt;[[Cornucopia_-_Ecommerce_Website_-_AZ_6|« Previous Card]] &amp;lt;span style=&amp;quot;padding-left:10px;padding-right:10px;&amp;quot;&amp;gt;|&amp;lt;/span&amp;gt;  [[Cornucopia_-_Ecommerce_Website_-_AZ|Authorization]] &amp;lt;span style=&amp;quot;padding-left:10px;padding-right:10px;&amp;quot;&amp;gt;|&amp;lt;/span&amp;gt; [[Cornucopia_-_Ecommerce_Website_-_AZ_8|Next Card »]] &amp;lt;/div&amp;gt;&lt;/div&gt;</summary>
		<author><name>Dariodf</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cornucopia_-_Ecommerce_Website_-_AZ_6&amp;diff=207198</id>
		<title>Cornucopia - Ecommerce Website - AZ 6</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cornucopia_-_Ecommerce_Website_-_AZ_6&amp;diff=207198"/>
				<updated>2016-01-21T16:24:28Z</updated>
		
		<summary type="html">&lt;p&gt;Dariodf: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{DISPLAYTITLE:&amp;lt;span style=&amp;quot;padding:2px 5px 0px 5px;color:white;background:#d9c049;&amp;quot;&amp;gt;Cornucopia - Ecommerce Website - AZ 6&amp;lt;/span&amp;gt;}}&lt;br /&gt;
[[File:Cornucopia_-_Ecommerce_Website_AZ_6.png|frame|right]]&lt;br /&gt;
'''Suit:''' [[Cornucopia_-_Ecommerce_Website_-_AZ|Authorization]]&lt;br /&gt;
&lt;br /&gt;
'''Card/Value:''' 6&lt;br /&gt;
&lt;br /&gt;
=== Description: ===&lt;br /&gt;
&lt;br /&gt;
Eduardo can access data he does not have permission to, even though he has permission to the form/page/URL/entry point.&lt;br /&gt;
&lt;br /&gt;
=== Technical Note: ===&lt;br /&gt;
&lt;br /&gt;
Even though a user may be permitted access to a particular page, the contents of that page should also verify access control privileges. For example, a user should be able to edit their own profile text, but not that for another user. Implement least privilege, and restrict users to only the data and system information that are required to perform their tasks.&lt;br /&gt;
&lt;br /&gt;
NB: the key concept for this card is applying authorization controls at the data level. See [[Cornucopia_-_Ecommerce_Website_-_AZ_5|AZ 5]] for resource types controls, and [[Cornucopia_-_Ecommerce_Website_-_AZ_7|AZ 7]] for function/object/property controls.&lt;br /&gt;
&lt;br /&gt;
=== References: ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;table class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center;&amp;quot;&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;OWASP SCP&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;OWASP ASVS&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;OWASP AppSensor&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;CAPEC&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;SAFECODE&amp;lt;/th&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#81|81]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Application_Security_Verification_Standard#4.1|4.1]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[AppSensor_DetectionPoints#ACE1|ACE1]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[https://capec.mitre.org/data/definitions/122.html 122]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[SAFECode_Practical_Security_Stories#8|8]]&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#88|88]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Application_Security_Verification_Standard#4.3|4.3]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[AppSensor_DetectionPoints#ACE2|ACE2]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[SAFECode_Practical_Security_Stories#10|10]]&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#131|131]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Application_Security_Verification_Standard#4.4|4.4]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[AppSensor_DetectionPoints#ACE3|ACE3]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[SAFECode_Practical_Security_Stories#11|11]]&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Application_Security_Verification_Standard#15.7|15.7]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[AppSensor_DetectionPoints#ACE4|ACE4]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;padding:5px;background:LightGray;color:White;font-weight:bold;&amp;quot;&amp;gt;[[Cornucopia_-_Ecommerce_Website_-_AZ_5|« Previous Card]] &amp;lt;span style=&amp;quot;padding-left:10px;padding-right:10px;&amp;quot;&amp;gt;|&amp;lt;/span&amp;gt;  [[Cornucopia_-_Ecommerce_Website_-_AZ|Authorization]] &amp;lt;span style=&amp;quot;padding-left:10px;padding-right:10px;&amp;quot;&amp;gt;|&amp;lt;/span&amp;gt; [[Cornucopia_-_Ecommerce_Website_-_AZ_7|Next Card »]] &amp;lt;/div&amp;gt;&lt;/div&gt;</summary>
		<author><name>Dariodf</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cornucopia_-_Ecommerce_Website_-_AZ_4&amp;diff=207197</id>
		<title>Cornucopia - Ecommerce Website - AZ 4</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cornucopia_-_Ecommerce_Website_-_AZ_4&amp;diff=207197"/>
				<updated>2016-01-21T16:24:04Z</updated>
		
		<summary type="html">&lt;p&gt;Dariodf: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{DISPLAYTITLE:&amp;lt;span style=&amp;quot;padding:2px 5px 0px 5px;color:white;background:#d9c049;&amp;quot;&amp;gt;Cornucopia - Ecommerce Website - AZ 4&amp;lt;/span&amp;gt;}}&lt;br /&gt;
[[File:Cornucopia_-_Ecommerce_Website_AZ_4.png|frame|right]]&lt;br /&gt;
'''Suit:''' [[Cornucopia_-_Ecommerce_Website_-_AZ|Authorization]]&lt;br /&gt;
&lt;br /&gt;
'''Card/Value:''' 4&lt;br /&gt;
&lt;br /&gt;
=== Description: ===&lt;br /&gt;
&lt;br /&gt;
Kelly can bypass authorization controls because they do not fail securely (i.e. they default to allowing access).&lt;br /&gt;
&lt;br /&gt;
=== Technical Note: ===&lt;br /&gt;
&lt;br /&gt;
Once an authorization failure is detected, access needs to be blocked.  It is also useful to log (associated with the user's identity if possible) and flag these as possibly malicious activity for further analysis, or as input for application intrusion detection systems.&lt;br /&gt;
&lt;br /&gt;
NB: the key concept for this card is permitting access, even though authorization checks were undertaken and detected a failure. See [[Cornucopia_-_Ecommerce_Website_-_AT_8|AT 8]] for the similar authentication failure.&lt;br /&gt;
&lt;br /&gt;
=== References: ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;table class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center;&amp;quot;&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;OWASP SCP&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;OWASP ASVS&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;OWASP AppSensor&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;CAPEC&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;SAFECODE&amp;lt;/th&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#79|79]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Application_Security_Verification_Standard#4.8|4.8]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[https://capec.mitre.org/data/definitions/122.html 122]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[SAFECode_Practical_Security_Stories#8|8]]&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#80|80]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[SAFECode_Practical_Security_Stories#10|10]]&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[SAFECode_Practical_Security_Stories#11|11]]&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;padding:5px;background:LightGray;color:White;font-weight:bold;&amp;quot;&amp;gt;[[Cornucopia_-_Ecommerce_Website_-_AZ_3|« Previous Card]] &amp;lt;span style=&amp;quot;padding-left:10px;padding-right:10px;&amp;quot;&amp;gt;|&amp;lt;/span&amp;gt;  [[Cornucopia_-_Ecommerce_Website_-_AZ|Authorization]] &amp;lt;span style=&amp;quot;padding-left:10px;padding-right:10px;&amp;quot;&amp;gt;|&amp;lt;/span&amp;gt; [[Cornucopia_-_Ecommerce_Website_-_AZ_5|Next Card »]] &amp;lt;/div&amp;gt;&lt;/div&gt;</summary>
		<author><name>Dariodf</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cornucopia_-_Ecommerce_Website_-_AZ_3&amp;diff=207196</id>
		<title>Cornucopia - Ecommerce Website - AZ 3</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cornucopia_-_Ecommerce_Website_-_AZ_3&amp;diff=207196"/>
				<updated>2016-01-21T16:23:53Z</updated>
		
		<summary type="html">&lt;p&gt;Dariodf: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{DISPLAYTITLE:&amp;lt;span style=&amp;quot;padding:2px 5px 0px 5px;color:white;background:#d9c049;&amp;quot;&amp;gt;Cornucopia - Ecommerce Website - AZ 3&amp;lt;/span&amp;gt;}}&lt;br /&gt;
[[File:Cornucopia_-_Ecommerce_Website_AZ_3.png|frame|right]]&lt;br /&gt;
'''Suit:''' [[Cornucopia_-_Ecommerce_Website_-_AZ|Authorization]]&lt;br /&gt;
&lt;br /&gt;
'''Card/Value:''' 3&lt;br /&gt;
&lt;br /&gt;
=== Description: ===&lt;br /&gt;
&lt;br /&gt;
Christian can access information, which they should not have permission to, through another mechanism that does have permission (e.g. search indexer, logger, reporting), or because it is cached, or kept for longer than necessary, or other information leakage.&lt;br /&gt;
&lt;br /&gt;
=== Technical Note: ===&lt;br /&gt;
&lt;br /&gt;
The attacker themselves is not permitted direct acecss, but has access to something, that had or has access to information. Consider all accounts/roles and what access privileges they have, and whether a user in one role can utilise another role. Create an Access Control Policy to document an application's business rules, data types and access authorization criteria and/or processes so that access can be properly provisioned and controlled. This includes identifying access requirements for both the data and system resources.&lt;br /&gt;
&lt;br /&gt;
This card also includes considerations of access to residual information such as cached data, data stored temporarily, and the inadequate deletion of information that is no longer required (and has passed its required retention period).&lt;br /&gt;
&lt;br /&gt;
=== References: ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;table class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center;&amp;quot;&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;OWASP SCP&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;OWASP ASVS&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;OWASP AppSensor&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;CAPEC&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;SAFECODE&amp;lt;/th&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#51|51]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Application_Security_Verification_Standard#4.1|4.1]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[https://capec.mitre.org/data/definitions/69.html 69]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[SAFECode_Practical_Security_Stories#8|8]]&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#100|100]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Application_Security_Verification_Standard#8.10|8.10]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[https://capec.mitre.org/data/definitions/213.html 213]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[SAFECode_Practical_Security_Stories#10|10]]&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#135|135]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Application_Security_Verification_Standard#9.1|9.1]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[SAFECode_Practical_Security_Stories#11|11]]&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#139|139]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Application_Security_Verification_Standard#9.2|9.2]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#140|140]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Application_Security_Verification_Standard#9.3|9.3]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#141|141]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Application_Security_Verification_Standard#9.4|9.4]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#150|150]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Application_Security_Verification_Standard#9.5|9.5]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Application_Security_Verification_Standard#9.6|9.6]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Application_Security_Verification_Standard#17.18|17.18]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;padding:5px;background:LightGray;color:White;font-weight:bold;&amp;quot;&amp;gt;[[Cornucopia_-_Ecommerce_Website_-_AZ_2|« Previous Card]] &amp;lt;span style=&amp;quot;padding-left:10px;padding-right:10px;&amp;quot;&amp;gt;|&amp;lt;/span&amp;gt;  [[Cornucopia_-_Ecommerce_Website_-_AZ|Authorization]] &amp;lt;span style=&amp;quot;padding-left:10px;padding-right:10px;&amp;quot;&amp;gt;|&amp;lt;/span&amp;gt; [[Cornucopia_-_Ecommerce_Website_-_AZ_4|Next Card »]] &amp;lt;/div&amp;gt;&lt;/div&gt;</summary>
		<author><name>Dariodf</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cornucopia_-_Ecommerce_Website_-_AZ_2&amp;diff=207195</id>
		<title>Cornucopia - Ecommerce Website - AZ 2</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cornucopia_-_Ecommerce_Website_-_AZ_2&amp;diff=207195"/>
				<updated>2016-01-21T16:23:41Z</updated>
		
		<summary type="html">&lt;p&gt;Dariodf: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{DISPLAYTITLE:&amp;lt;span style=&amp;quot;padding:2px 5px 0px 5px;color:white;background:#d9c049;&amp;quot;&amp;gt;Cornucopia - Ecommerce Website - AZ 2&amp;lt;/span&amp;gt;}}&lt;br /&gt;
[[File:Cornucopia_-_Ecommerce_Website_AZ_2.png|frame|right]]&lt;br /&gt;
'''Suit:''' [[Cornucopia_-_Ecommerce_Website_-_AZ|Authorization]]&lt;br /&gt;
&lt;br /&gt;
'''Card/Value:''' 2&lt;br /&gt;
&lt;br /&gt;
=== Description: ===&lt;br /&gt;
&lt;br /&gt;
Tim can influence where data is sent or forwarded to.&lt;br /&gt;
&lt;br /&gt;
=== Technical Note: ===&lt;br /&gt;
&lt;br /&gt;
Users must not be able to define unauthorised virtual locations/addresses such as:&lt;br /&gt;
* Database table names.&lt;br /&gt;
* File system paths.&lt;br /&gt;
* Alert SMS or email messages.&lt;br /&gt;
* URL paths.&lt;br /&gt;
&lt;br /&gt;
All such properties must be defined by the ecommerce application itself, or drawn from a valid list of locations permitted for the user and their role.&lt;br /&gt;
&lt;br /&gt;
=== References: ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;table class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center;&amp;quot;&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;OWASP SCP&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;OWASP ASVS&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;OWASP AppSensor&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;CAPEC&amp;lt;/th&amp;gt;&lt;br /&gt;
    &amp;lt;th&amp;gt;SAFECODE&amp;lt;/th&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#44|44]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Application_Security_Verification_Standard#4.3|4.3]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[https://capec.mitre.org/data/definitions/153.html 153]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[SAFECode_Practical_Security_Stories#8|8]]&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Application_Security_Verification_Standard#15.7|15.7]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[SAFECode_Practical_Security_Stories#10|10]]&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
  &amp;lt;tr&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[OWASP_Application_Security_Verification_Standard#16.1|16.1]]&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
    &amp;lt;td&amp;gt;[[SAFECode_Practical_Security_Stories#11|11]]&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;padding:5px;background:LightGray;color:White;font-weight:bold;&amp;quot;&amp;gt;[[Cornucopia_-_Ecommerce_Website_-_SM_A|« Previous Card]] &amp;lt;span style=&amp;quot;padding-left:10px;padding-right:10px;&amp;quot;&amp;gt;|&amp;lt;/span&amp;gt;  [[Cornucopia_-_Ecommerce_Website_-_AZ|Authorization]] &amp;lt;span style=&amp;quot;padding-left:10px;padding-right:10px;&amp;quot;&amp;gt;|&amp;lt;/span&amp;gt; [[Cornucopia_-_Ecommerce_Website_-_AZ_3|Next Card »]] &amp;lt;/div&amp;gt;&lt;/div&gt;</summary>
		<author><name>Dariodf</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cornucopia_-_Ecommerce_Website_-_SM_A&amp;diff=207194</id>
		<title>Cornucopia - Ecommerce Website - SM A</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cornucopia_-_Ecommerce_Website_-_SM_A&amp;diff=207194"/>
				<updated>2016-01-21T16:23:31Z</updated>
		
		<summary type="html">&lt;p&gt;Dariodf: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{DISPLAYTITLE:&amp;lt;span style=&amp;quot;padding:2px 5px 0px 5px;color:white;background:#98c477;&amp;quot;&amp;gt;Cornucopia - Ecommerce Website - SM A&amp;lt;/span&amp;gt;}}&lt;br /&gt;
[[File:Cornucopia_-_Ecommerce_Website_SM_A.png|frame|right]]&lt;br /&gt;
'''Suit:''' [[Cornucopia_-_Ecommerce_Website_-_SM|Session management]]&lt;br /&gt;
&lt;br /&gt;
'''Card/Value:''' A&lt;br /&gt;
&lt;br /&gt;
=== Description: ===&lt;br /&gt;
&lt;br /&gt;
You have invented a new attack against Session Management&lt;br /&gt;
&lt;br /&gt;
=== Technical Note: ===&lt;br /&gt;
&lt;br /&gt;
Players can discuss any type of Session Management (SM) attack they think might be possible against the assessment target. It does not matter if the attack relates to another [[Cornucopia_-_Ecommerce_Website_-_SM|SM]] card, but if possible try to identify an attack that is fairly unique to the application/functionality/users.&lt;br /&gt;
&lt;br /&gt;
=== References: ===&lt;br /&gt;
&lt;br /&gt;
Read more about this topic in OWASP’s free Cheat Sheets on Session Management, and Cross Site Request Forgery (CSRF) Prevention&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;padding:5px;background:LightGray;color:White;font-weight:bold;&amp;quot;&amp;gt;[[Cornucopia_-_Ecommerce_Website_-_SM_K|« Previous Card]] &amp;lt;span style=&amp;quot;padding-left:10px;padding-right:10px;&amp;quot;&amp;gt;|&amp;lt;/span&amp;gt;  [[Cornucopia_-_Ecommerce_Website_-_SM|Session management]] &amp;lt;span style=&amp;quot;padding-left:10px;padding-right:10px;&amp;quot;&amp;gt;|&amp;lt;/span&amp;gt; [[Cornucopia_-_Ecommerce_Website_-_AZ_2|Next Card »]] &amp;lt;/div&amp;gt;&lt;/div&gt;</summary>
		<author><name>Dariodf</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cornucopia_-_Ecommerce_Website_-_SM_K&amp;diff=207193</id>
		<title>Cornucopia - Ecommerce Website - SM K</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cornucopia_-_Ecommerce_Website_-_SM_K&amp;diff=207193"/>
				<updated>2016-01-21T16:23:10Z</updated>
		
		<summary type="html">&lt;p&gt;Dariodf: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{DISPLAYTITLE:&amp;lt;span style=&amp;quot;padding:2px 5px 0px 5px;color:white;background:#98c477;&amp;quot;&amp;gt;Cornucopia - Ecommerce Website - SM K&amp;lt;/span&amp;gt;}}&lt;br /&gt;
[[File:Cornucopia_-_Ecommerce_Website_SM_K.png|frame|right]]&lt;br /&gt;
'''Suit:''' [[Cornucopia_-_Ecommerce_Website_-_SM|Session management]]&lt;br /&gt;
&lt;br /&gt;
'''Card/Value:''' K&lt;br /&gt;
&lt;br /&gt;
=== Description: ===&lt;br /&gt;
&lt;br /&gt;
Peter can bypass the session management controls because they have been self-built and/or are weak, instead of using a standard framework or approved tested module.&lt;br /&gt;
&lt;br /&gt;
=== Technical Note: ===&lt;br /&gt;
&lt;br /&gt;
Centralized session management routines are a good programming practice, but like other routines, developers need to understand how they work, how to use them and any limitations. These should preferably be the framework's in-built session management support. If third party session management libraries are used, it is important to test each routine before its implementation.&lt;br /&gt;
&lt;br /&gt;
NB: This relates to what session management routines to use. See [[Cornucopia_-_Ecommerce_Website_-_SM_Q|SM Q]] for application-wide coverage.&lt;br /&gt;
&lt;br /&gt;
=== References: ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;table class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center;&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;tr class=&amp;quot;tableizer-firstrow&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;th&amp;gt;OWASP SCP&amp;lt;/th&amp;gt;&lt;br /&gt;
&amp;lt;th&amp;gt;OWASP ASVS&amp;lt;/th&amp;gt;&lt;br /&gt;
&amp;lt;th&amp;gt;OWASP AppSensor&amp;lt;/th&amp;gt;&lt;br /&gt;
&amp;lt;th&amp;gt;CAPEC&amp;lt;/th&amp;gt;&lt;br /&gt;
&amp;lt;th&amp;gt;SAFECODE&amp;lt;/th&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#58|58]]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[[OWASP_Application_Security_Verification_Standard#3.1|3.1]]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[https://capec.mitre.org/data/definitions/21.html 21]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[[SAFECode_Practical_Security_Stories#14|14]]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#60|60]]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[[SAFECode_Practical_Security_Stories#28|28]]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;padding:5px;background:LightGray;color:White;font-weight:bold;&amp;quot;&amp;gt;[[Cornucopia_-_Ecommerce_Website_-_SM_Q|« Previous Card]] &amp;lt;span style=&amp;quot;padding-left:10px;padding-right:10px;&amp;quot;&amp;gt;|&amp;lt;/span&amp;gt;  [[Cornucopia_-_Ecommerce_Website_-_SM|Session management]] &amp;lt;span style=&amp;quot;padding-left:10px;padding-right:10px;&amp;quot;&amp;gt;|&amp;lt;/span&amp;gt; [[Cornucopia_-_Ecommerce_Website_-_SM_A|Next Card »]] &amp;lt;/div&amp;gt;&lt;/div&gt;</summary>
		<author><name>Dariodf</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cornucopia_-_Ecommerce_Website_-_SM_Q&amp;diff=207192</id>
		<title>Cornucopia - Ecommerce Website - SM Q</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cornucopia_-_Ecommerce_Website_-_SM_Q&amp;diff=207192"/>
				<updated>2016-01-21T16:22:56Z</updated>
		
		<summary type="html">&lt;p&gt;Dariodf: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{DISPLAYTITLE:&amp;lt;span style=&amp;quot;padding:2px 5px 0px 5px;color:white;background:#98c477;&amp;quot;&amp;gt;Cornucopia - Ecommerce Website - SM Q&amp;lt;/span&amp;gt;}}&lt;br /&gt;
[[File:Cornucopia_-_Ecommerce_Website_SM_Q.png|frame|right]]&lt;br /&gt;
'''Suit:''' [[Cornucopia_-_Ecommerce_Website_-_SM|Session management]]&lt;br /&gt;
&lt;br /&gt;
'''Card/Value:''' Q&lt;br /&gt;
&lt;br /&gt;
=== Description: ===&lt;br /&gt;
&lt;br /&gt;
Salim can bypass session management because it is not applied comprehensively and consistently across the application.&lt;br /&gt;
&lt;br /&gt;
=== Technical Note: ===&lt;br /&gt;
&lt;br /&gt;
Every part of the application and type of request should verify that the user has a valid current session (if required) and thus their privileges, before undertaking any other data validation and processing.&lt;br /&gt;
&lt;br /&gt;
NB: This relates to application-wide session management control. See [[Cornucopia_-_Ecommerce_Website_-_SM_K|SM K]] for what session management routines to use.&lt;br /&gt;
&lt;br /&gt;
=== References: ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;table class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center;&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;tr class=&amp;quot;tableizer-firstrow&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;th&amp;gt;OWASP SCP&amp;lt;/th&amp;gt;&lt;br /&gt;
&amp;lt;th&amp;gt;OWASP ASVS&amp;lt;/th&amp;gt;&lt;br /&gt;
&amp;lt;th&amp;gt;OWASP AppSensor&amp;lt;/th&amp;gt;&lt;br /&gt;
&amp;lt;th&amp;gt;CAPEC&amp;lt;/th&amp;gt;&lt;br /&gt;
&amp;lt;th&amp;gt;SAFECODE&amp;lt;/th&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#58|58]]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[[OWASP_Application_Security_Verification_Standard#3.1|3.1]]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[https://capec.mitre.org/data/definitions/21.html 21]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[[SAFECode_Practical_Security_Stories#14|14]]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[[SAFECode_Practical_Security_Stories#28|28]]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;padding:5px;background:LightGray;color:White;font-weight:bold;&amp;quot;&amp;gt;[[Cornucopia_-_Ecommerce_Website_-_SM_J|« Previous Card]] &amp;lt;span style=&amp;quot;padding-left:10px;padding-right:10px;&amp;quot;&amp;gt;|&amp;lt;/span&amp;gt;  [[Cornucopia_-_Ecommerce_Website_-_SM|Session management]] &amp;lt;span style=&amp;quot;padding-left:10px;padding-right:10px;&amp;quot;&amp;gt;|&amp;lt;/span&amp;gt; [[Cornucopia_-_Ecommerce_Website_-_SM_K|Next Card »]] &amp;lt;/div&amp;gt;&lt;/div&gt;</summary>
		<author><name>Dariodf</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cornucopia_-_Ecommerce_Website_-_SM_J&amp;diff=207191</id>
		<title>Cornucopia - Ecommerce Website - SM J</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cornucopia_-_Ecommerce_Website_-_SM_J&amp;diff=207191"/>
				<updated>2016-01-21T16:22:37Z</updated>
		
		<summary type="html">&lt;p&gt;Dariodf: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{DISPLAYTITLE:&amp;lt;span style=&amp;quot;padding:2px 5px 0px 5px;color:white;background:#98c477;&amp;quot;&amp;gt;Cornucopia - Ecommerce Website - SM J&amp;lt;/span&amp;gt;}}&lt;br /&gt;
[[File:Cornucopia_-_Ecommerce_Website_SM_J.png|frame|right]]&lt;br /&gt;
'''Suit:''' [[Cornucopia_-_Ecommerce_Website_-_SM|Session management]]&lt;br /&gt;
&lt;br /&gt;
'''Card/Value:''' J&lt;br /&gt;
&lt;br /&gt;
=== Description: ===&lt;br /&gt;
&lt;br /&gt;
Jeff can resend an identical repeat interaction (e.g. HTTP request, signal, button press) and it is accepted, not rejected.&lt;br /&gt;
&lt;br /&gt;
=== Technical Note: ===&lt;br /&gt;
&lt;br /&gt;
The key concept for this card is replay of a previous event.&lt;br /&gt;
&lt;br /&gt;
=== References: ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;table class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center;&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;tr class=&amp;quot;tableizer-firstrow&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;th&amp;gt;OWASP SCP&amp;lt;/th&amp;gt;&lt;br /&gt;
&amp;lt;th&amp;gt;OWASP ASVS&amp;lt;/th&amp;gt;&lt;br /&gt;
&amp;lt;th&amp;gt;OWASP AppSensor&amp;lt;/th&amp;gt;&lt;br /&gt;
&amp;lt;th&amp;gt;CAPEC&amp;lt;/th&amp;gt;&lt;br /&gt;
&amp;lt;th&amp;gt;SAFECODE&amp;lt;/th&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[[OWASP_Application_Security_Verification_Standard#15.2|15.2]]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[[AppSensor_DetectionPoints#IE5|IE5]]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[https://capec.mitre.org/data/definitions/60.html 60]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[[SAFECode_Practical_Security_Stories#12|12]]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[[SAFECode_Practical_Security_Stories#14|14]]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;padding:5px;background:LightGray;color:White;font-weight:bold;&amp;quot;&amp;gt;[[Cornucopia_-_Ecommerce_Website_-_SM_10|« Previous Card]] &amp;lt;span style=&amp;quot;padding-left:10px;padding-right:10px;&amp;quot;&amp;gt;|&amp;lt;/span&amp;gt;  [[Cornucopia_-_Ecommerce_Website_-_SM|Session management]] &amp;lt;span style=&amp;quot;padding-left:10px;padding-right:10px;&amp;quot;&amp;gt;|&amp;lt;/span&amp;gt; [[Cornucopia_-_Ecommerce_Website_-_SM_Q|Next Card »]] &amp;lt;/div&amp;gt;&lt;/div&gt;</summary>
		<author><name>Dariodf</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cornucopia_-_Ecommerce_Website_-_SM_10&amp;diff=207190</id>
		<title>Cornucopia - Ecommerce Website - SM 10</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cornucopia_-_Ecommerce_Website_-_SM_10&amp;diff=207190"/>
				<updated>2016-01-21T16:22:01Z</updated>
		
		<summary type="html">&lt;p&gt;Dariodf: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{DISPLAYTITLE:&amp;lt;span style=&amp;quot;padding:2px 5px 0px 5px;color:white;background:#98c477;&amp;quot;&amp;gt;Cornucopia - Ecommerce Website - SM 10&amp;lt;/span&amp;gt;}}&lt;br /&gt;
[[File:Cornucopia_-_Ecommerce_Website_SM_10.png|frame|right]]&lt;br /&gt;
'''Suit:''' [[Cornucopia_-_Ecommerce_Website_-_SM|Session management]]&lt;br /&gt;
&lt;br /&gt;
'''Card/Value:''' 10&lt;br /&gt;
&lt;br /&gt;
=== Description: ===&lt;br /&gt;
&lt;br /&gt;
Marce can forge requests because per-session, or per-request for more critical actions, strong random tokens (i.e. anti-CSRF tokens) or similar are not being used for actions that change state.&lt;br /&gt;
&lt;br /&gt;
=== Technical Note: ===&lt;br /&gt;
&lt;br /&gt;
Consider supplementing standard session management with:&lt;br /&gt;
* Per-session strong random tokens or parameters.&lt;br /&gt;
* Per-request, as opposed to per-session, strong random tokens or parameters.&lt;br /&gt;
&lt;br /&gt;
=== References: ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;table class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center;&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;tr class=&amp;quot;tableizer-firstrow&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;th&amp;gt;OWASP SCP&amp;lt;/th&amp;gt;&lt;br /&gt;
&amp;lt;th&amp;gt;OWASP ASVS&amp;lt;/th&amp;gt;&lt;br /&gt;
&amp;lt;th&amp;gt;OWASP AppSensor&amp;lt;/th&amp;gt;&lt;br /&gt;
&amp;lt;th&amp;gt;CAPEC&amp;lt;/th&amp;gt;&lt;br /&gt;
&amp;lt;th&amp;gt;SAFECODE&amp;lt;/th&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#73|73]]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[[OWASP_Application_Security_Verification_Standard#4.16|4.16]]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[[AppSensor_DetectionPoints#IE4|IE4]]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[https://capec.mitre.org/data/definitions/62.html 62]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[[SAFECode_Practical_Security_Stories#18|18]]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#74|74]]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[https://capec.mitre.org/data/definitions/111.html 111]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;padding:5px;background:LightGray;color:White;font-weight:bold;&amp;quot;&amp;gt;[[Cornucopia_-_Ecommerce_Website_-_SM_9|« Previous Card]] &amp;lt;span style=&amp;quot;padding-left:10px;padding-right:10px;&amp;quot;&amp;gt;|&amp;lt;/span&amp;gt;  [[Cornucopia_-_Ecommerce_Website_-_SM|Session management]] &amp;lt;span style=&amp;quot;padding-left:10px;padding-right:10px;&amp;quot;&amp;gt;|&amp;lt;/span&amp;gt; [[Cornucopia_-_Ecommerce_Website_-_SM_J|Next Card »]] &amp;lt;/div&amp;gt;&lt;/div&gt;</summary>
		<author><name>Dariodf</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cornucopia_-_Ecommerce_Website_-_SM_9&amp;diff=207189</id>
		<title>Cornucopia - Ecommerce Website - SM 9</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cornucopia_-_Ecommerce_Website_-_SM_9&amp;diff=207189"/>
				<updated>2016-01-21T16:21:49Z</updated>
		
		<summary type="html">&lt;p&gt;Dariodf: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{DISPLAYTITLE:&amp;lt;span style=&amp;quot;padding:2px 5px 0px 5px;color:white;background:#98c477;&amp;quot;&amp;gt;Cornucopia - Ecommerce Website - SM 9&amp;lt;/span&amp;gt;}}&lt;br /&gt;
[[File:Cornucopia_-_Ecommerce_Website_SM_9.png|frame|right]]&lt;br /&gt;
'''Suit:''' [[Cornucopia_-_Ecommerce_Website_-_SM|Session management]]&lt;br /&gt;
&lt;br /&gt;
'''Card/Value:''' 9&lt;br /&gt;
&lt;br /&gt;
=== Description: ===&lt;br /&gt;
&lt;br /&gt;
Ivan can steal session identifiers because they are sent over insecure channels, or are logged, or are revealed in error messages, or are included in URLs, or are accessible unnecessarily by code which the attacker can influence or alter.&lt;br /&gt;
&lt;br /&gt;
=== Technical Note: ===&lt;br /&gt;
&lt;br /&gt;
Protect session identifiers as if they are account credentials. For HTTP cookies:&lt;br /&gt;
* Set cookies with the HttpOnly attribute, unless you specifically require client-side scripts within your application to read or set a cookie's value.&lt;br /&gt;
* Set the 'secure' attribute for cookies transmitted over an TLS connection.&lt;br /&gt;
* Consider making the whole ecommerce website 'SSL-only', adding the HTTP Strict Transport Security (HSTS) header and adding the domain to web browser pre-load lists.&lt;br /&gt;
&lt;br /&gt;
=== References: ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;table class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center;&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;tr class=&amp;quot;tableizer-firstrow&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;th&amp;gt;OWASP SCP&amp;lt;/th&amp;gt;&lt;br /&gt;
&amp;lt;th&amp;gt;OWASP ASVS&amp;lt;/th&amp;gt;&lt;br /&gt;
&amp;lt;th&amp;gt;OWASP AppSensor&amp;lt;/th&amp;gt;&lt;br /&gt;
&amp;lt;th&amp;gt;CAPEC&amp;lt;/th&amp;gt;&lt;br /&gt;
&amp;lt;th&amp;gt;SAFECODE&amp;lt;/th&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#69|69]]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[[OWASP_Application_Security_Verification_Standard#3.6|3.6]]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[[AppSensor_DetectionPoints#SE4|SE4]]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[https://capec.mitre.org/data/definitions/31.html 31]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[[SAFECode_Practical_Security_Stories#28|28]]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#75|75]]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[[OWASP_Application_Security_Verification_Standard#3.14|3.14]]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[[AppSensor_DetectionPoints#SE5|SE5]]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[https://capec.mitre.org/data/definitions/60.html 60]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#76|76]]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[[OWASP_Application_Security_Verification_Standard#3.15|3.15]]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[[AppSensor_DetectionPoints#SE6|SE6]]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#119|119]]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[[OWASP_Application_Security_Verification_Standard#8.10|8.10]]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#138|138]]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[[OWASP_Application_Security_Verification_Standard#10.3|10.3]]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;padding:5px;background:LightGray;color:White;font-weight:bold;&amp;quot;&amp;gt;[[Cornucopia_-_Ecommerce_Website_-_SM_8|« Previous Card]] &amp;lt;span style=&amp;quot;padding-left:10px;padding-right:10px;&amp;quot;&amp;gt;|&amp;lt;/span&amp;gt;  [[Cornucopia_-_Ecommerce_Website_-_SM|Session management]] &amp;lt;span style=&amp;quot;padding-left:10px;padding-right:10px;&amp;quot;&amp;gt;|&amp;lt;/span&amp;gt; [[Cornucopia_-_Ecommerce_Website_-_SM_10|Next Card »]] &amp;lt;/div&amp;gt;&lt;/div&gt;</summary>
		<author><name>Dariodf</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cornucopia_-_Ecommerce_Website_-_SM_8&amp;diff=207188</id>
		<title>Cornucopia - Ecommerce Website - SM 8</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cornucopia_-_Ecommerce_Website_-_SM_8&amp;diff=207188"/>
				<updated>2016-01-21T16:21:40Z</updated>
		
		<summary type="html">&lt;p&gt;Dariodf: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{DISPLAYTITLE:&amp;lt;span style=&amp;quot;padding:2px 5px 0px 5px;color:white;background:#98c477;&amp;quot;&amp;gt;Cornucopia - Ecommerce Website - SM 8&amp;lt;/span&amp;gt;}}&lt;br /&gt;
[[File:Cornucopia_-_Ecommerce_Website_SM_8.png|frame|right]]&lt;br /&gt;
'''Suit:''' [[Cornucopia_-_Ecommerce_Website_-_SM|Session management]]&lt;br /&gt;
&lt;br /&gt;
'''Card/Value:''' 8&lt;br /&gt;
&lt;br /&gt;
=== Description: ===&lt;br /&gt;
&lt;br /&gt;
Matt can abuse long sessions because the application does not require periodic re-authentication to check if privileges have changed.&lt;br /&gt;
&lt;br /&gt;
=== Technical Note: ===&lt;br /&gt;
&lt;br /&gt;
A user's privileges may change during a session. If this information is also stored in session data, it will not reflect the changes. Consider forcing re-authentication.&lt;br /&gt;
&lt;br /&gt;
See Authentication [[Cornucopia_-_Ecommerce_Website_-_AT_9|AT 9]] for other re-authentication requirements.&lt;br /&gt;
&lt;br /&gt;
=== References: ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;table class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center;&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;tr class=&amp;quot;tableizer-firstrow&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;th&amp;gt;OWASP SCP&amp;lt;/th&amp;gt;&lt;br /&gt;
&amp;lt;th&amp;gt;OWASP ASVS&amp;lt;/th&amp;gt;&lt;br /&gt;
&amp;lt;th&amp;gt;OWASP AppSensor&amp;lt;/th&amp;gt;&lt;br /&gt;
&amp;lt;th&amp;gt;CAPEC&amp;lt;/th&amp;gt;&lt;br /&gt;
&amp;lt;th&amp;gt;SAFECODE&amp;lt;/th&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#96|96]]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[https://capec.mitre.org/data/definitions/21.html 21]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[[SAFECode_Practical_Security_Stories#28|28]]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;padding:5px;background:LightGray;color:White;font-weight:bold;&amp;quot;&amp;gt;[[Cornucopia_-_Ecommerce_Website_-_SM_7|« Previous Card]] &amp;lt;span style=&amp;quot;padding-left:10px;padding-right:10px;&amp;quot;&amp;gt;|&amp;lt;/span&amp;gt;  [[Cornucopia_-_Ecommerce_Website_-_SM|Session management]] &amp;lt;span style=&amp;quot;padding-left:10px;padding-right:10px;&amp;quot;&amp;gt;|&amp;lt;/span&amp;gt; [[Cornucopia_-_Ecommerce_Website_-_SM_9|Next Card »]] &amp;lt;/div&amp;gt;&lt;/div&gt;</summary>
		<author><name>Dariodf</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cornucopia_-_Ecommerce_Website_-_SM_8&amp;diff=207187</id>
		<title>Cornucopia - Ecommerce Website - SM 8</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cornucopia_-_Ecommerce_Website_-_SM_8&amp;diff=207187"/>
				<updated>2016-01-21T16:21:32Z</updated>
		
		<summary type="html">&lt;p&gt;Dariodf: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{DISPLAYTITLE:&amp;lt;span style=&amp;quot;padding:2px 5px 0px 5px;color:white;background:#98c477;&amp;quot;&amp;gt;Cornucopia - Ecommerce Website - SM 8&amp;lt;/span&amp;gt;}}&lt;br /&gt;
[[File:Cornucopia_-_Ecommerce_Website_SM_8.png|frame|right]]&lt;br /&gt;
'''Suit:''' [[Cornucopia_-_Ecommerce_Website_-_SM|Session management]]&lt;br /&gt;
&lt;br /&gt;
'''Card/Value:''' 8&lt;br /&gt;
&lt;br /&gt;
=== Description: ===&lt;br /&gt;
&lt;br /&gt;
Matt can abuse long sessions because the application does not require periodic re-authentication to check if privileges have changed.&lt;br /&gt;
&lt;br /&gt;
=== Technical Note: ===&lt;br /&gt;
&lt;br /&gt;
A user's privileges may change during a session. If this information is also stored in session data, it will not reflect the changes. Consider forcing re-authentication.&lt;br /&gt;
&lt;br /&gt;
See Authentication [[Cornucopia_-_Ecommerce_Website_-_AT_9|AT 9]] for other re-authentication requirements.&lt;br /&gt;
&lt;br /&gt;
=== References: ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;table class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center;&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;tr class=&amp;quot;tableizer-firstrow&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;th&amp;gt;OWASP SCP&amp;lt;/th&amp;gt;&lt;br /&gt;
&amp;lt;th&amp;gt;OWASP ASVS&amp;lt;/th&amp;gt;&lt;br /&gt;
&amp;lt;th&amp;gt;OWASP AppSensor&amp;lt;/th&amp;gt;&lt;br /&gt;
&amp;lt;th&amp;gt;CAPEC&amp;lt;/th&amp;gt;&lt;br /&gt;
&amp;lt;th&amp;gt;SAFECODE&amp;lt;/th&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[[OWASP_Secure_Coding_Practices_Checklist#96|96]]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;-&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[https://capec.mitre.org/data/definitions/21.html 21]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;[[SAFECode_Practical_Security_Stories#28|28]]&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;padding:5px;background:LightGray;color:White;font-weight:bold;&amp;quot;&amp;gt;[[Cornucopia_-_Ecommerce_Website_-_SM_7|« Previous Card]] &amp;lt;span style=&amp;quot;padding-left:10px;padding-right:10px;&amp;quot;&amp;gt;|&amp;lt;/span&amp;gt;  [[Cornucopia_-_Ecommerce_Website_-_SM|Session management]] &amp;lt;span style=&amp;quot;padding-left:10px;padding-right:10px;&amp;quot;&amp;gt;|&amp;lt;/span&amp;gt; [[Cornucopia_-_Ecommerce_Website_-_SM_9|Next Card »]] &amp;lt;/div&amp;gt;&lt;/div&gt;</summary>
		<author><name>Dariodf</name></author>	</entry>

	</feed>