This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org
OWASP .NET Recommended Resources
OWASP .NET Quick Reference |
---|
OWASP .NET Recommended Resources
This is a canonical list of outside resources for .NET developers seeking security information.
Blogs & People
Advisories, Articles & Projects
Security and Operational Guidance for .NET Applications
patterns & practices Security Engineering Index
patterns & practices Security Guidance for Applications Index
patterns & practices Security Guidance for .NET Framework 2.0
Authentication in ASP.NET: .NET Security Guidance
Security Guidance for Windows Communication Foundation
Microsoft Security Advisory (954462) (SQL Injection Advisory)
Security Development Lifecycle
Online References, Training
MSDN Security Developer Center
Pluralsight Security Course Catalog
OWASP Top 10 for .NET developers - Troy Hunt
Security in the .NET Framework
Books and Publications
Writing Secure Code, Michael Howard and David LeBlanc
Microsoft Security Development Lifecycle 3.2
Building Secure ASP.NET Applications: Authentication, Authorization, and Secure Communication, J.D. Meier, Alex Mackman, Michael Dunner, and Srinath Vasireddy
Improving Web Application Security: Threats and Countermeasures, J.D. Meier, Alex Mackman, Michael Dunner, Srinath Vasireddy, Ray Escamilla and Anandha Murukan
Developer Highway Code, Microsoft Corp, United Kingdom
Security Driven .NET, Stan Drapkin
Tools
Microsoft Threat Modeling Tool 2014
Microsoft Source Code Analyzer