This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org

Difference between revisions of "OWASP Security JDIs Project"

From OWASP
Jump to: navigation, search
m
m (Overview)
 
(3 intermediate revisions by one other user not shown)
Line 1: Line 1:
 +
{|
 +
|-
 +
! width="700" align="center" | <br>
 +
! width="500" align="center" | <br>
 +
|-
 +
| align="right" | [[Image:OWASP Inactive Banner.jpg|800px| link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Inactive_Projects]]
 +
| align="right" |
 +
 +
|}
 
==Overview==
 
==Overview==
  
 
The aim of this project is to build up a [[OWASP_Security_JDIs|collection of practical solutions]] to specific security problems.
 
The aim of this project is to build up a [[OWASP_Security_JDIs|collection of practical solutions]] to specific security problems.
  
Rather than give explanations of security issues and defensive techniques - something which is done by Cheat Sheets and HOWTOs -  
+
Rather than give explanations of security issues and defensive techniques - something which is already done by Cheat Sheets and HOWTOs -  
 
the JDIs will consist of detailed, explicit instructions addressing specific issues using specific technology.
 
the JDIs will consist of detailed, explicit instructions addressing specific issues using specific technology.
  

Latest revision as of 18:02, 16 May 2017



OWASP Inactive Banner.jpg

Overview

The aim of this project is to build up a collection of practical solutions to specific security problems.

Rather than give explanations of security issues and defensive techniques - something which is already done by Cheat Sheets and HOWTOs - the JDIs will consist of detailed, explicit instructions addressing specific issues using specific technology.

Like recipes, a JDI may suit some tastes more than others and, again like recipes, there can be more than one JDI for the same problem.

The benefits will be

  • practical, if limited, solutions for developers without them first having to become an expert in the problem space - something which time often does not permit
  • usable code which can be a practical introduction to defensive technologies, such as ESAPI, AntiSamy, etc.

The project will

  1. endeavour to source a suitable solutions to specific, practical problems on request, and
  2. adopt solutions already developed by developers and/or security specialists which they would like to share.

Project Pages

JDI Collection

Development Process

JDI Pro-forma

OWASP Project Page

Roadmap