|
|
(33 intermediate revisions by 7 users not shown) |
Line 1: |
Line 1: |
− | [http://s1.shard.jp/frhorton/q8nii8ad3.html pictures of zambia africa
| + | {{Inactive Chapter}} |
− | ] [http://s1.shard.jp/bireba/antivirus-mcafee.html antivirus mcafee free anti virus software] [http://s1.shard.jp/bireba/mac-antivirus.html antivirus download for free
| |
− | ] [http://s1.shard.jp/frhorton/vwktsknc4.html africa water pump
| |
− | ] [http://s1.shard.jp/frhorton/78vbl98c2.html africa animal endangered south] [http://s1.shard.jp/losaul/australian-residency.html australian residency for new zealanders] [http://s1.shard.jp/galeach/new42.html ancient asian religions] [http://s1.shard.jp/bireba/symantec-antivirus.html northon antivirus
| |
− | ] [http://s1.shard.jp/bireba/ca-etrust-antivirus.html mac affee antivirus
| |
− | ] [http://s1.shard.jp/olharder/autoroll-654.html page] [http://s1.shard.jp/olharder/autoroll-654.html url] [http://s1.shard.jp/frhorton/qwl7aihru.html largest waterfall africa
| |
− | ] [http://s1.shard.jp/galeach/new71.html asian eye make up tips
| |
− | ] [http://s1.shard.jp/bireba/norton-antivirus.html norton antivirus definitions update download] [http://s1.shard.jp/frhorton/vuku1m6uz.html africa history togo] [http://s1.shard.jp/olharder/autobiographer.html auto body repair step by step
| |
− | ] [http://s1.shard.jp/losaul/the-lakes-golf.html australia rmit university
| |
− | ] [http://s1.shard.jp/bireba/antivirus-software.html panda antivirus platinum 7.04.00 crack
| |
− | ] [http://s1.shard.jp/frhorton/uu2d3yy8s.html business for sale in cape town south africa
| |
− | ] [http://s1.shard.jp/frhorton/9vces3l25.html african american trivia quiz
| |
− | ] [http://s1.shard.jp/losaul/cheap-air-fare-to.html australian health care summit
| |
− | ] [http://s1.shard.jp/olharder/autopilots-for.html autopilots for sale] [http://s1.shard.jp/losaul/australia-immigration.html panasonic australia
| |
− | ] [http://s1.shard.jp/bireba/panda-antivirus.html pc magazine antivirus
| |
− | ] [http://s1.shard.jp/olharder/autoroll-654.html index] [http://s1.shard.jp/losaul/rolling-stones.html management accountants australia
| |
− | ] [http://s1.shard.jp/frhorton/yzxhrnmp9.html african american gold jewelry
| |
− | ] [http://s1.shard.jp/bireba/panda-software.html panda titanium antivirus 2005 download
| |
− | ] [http://s1.shard.jp/galeach/new48.html asian women black guys
| |
− | ] [http://s1.shard.jp/bireba/antivirus-firewall.html mcafee home free antivirus
| |
− | ] [http://s1.shard.jp/galeach/new62.html lily thai mrchewsasianbeaver.com
| |
− | ] [http://s1.shard.jp/frhorton/wlyxxgvnc.html die son newspaper south africa
| |
− | ] [http://s1.shard.jp/bireba/panda-titanium.html top rated antivirus programs
| |
− | ] [http://s1.shard.jp/olharder/auto-calculator.html dental autoclave
| |
− | ] [http://s1.shard.jp/bireba/norton-antivirus.html norton antivirus free download software] [http://s1.shard.jp/galeach/new15.html asia argento scarlet diva
| |
− | ] [http://s1.shard.jp/frhorton/kqcuriisf.html the eastafrican standard
| |
− | ] [http://s1.shard.jp/galeach/new169.html is euthanasia right
| |
− | ] [http://s1.shard.jp/frhorton/pr9rl67ra.html africans girls
| |
− | ] [http://s1.shard.jp/bireba/escan-antivirus.html vet antivirus updates
| |
− | ] [http://s1.shard.jp/olharder/autoroll-654.html map] [http://s1.shard.jp/frhorton/8fsjs64q2.html ngo jobs in africa
| |
− | ] [http://s1.shard.jp/frhorton/1euh2vemn.html african baby gray parrot picture] [http://s1.shard.jp/galeach/new51.html asian clip homegrown
| |
− | ] [http://s1.shard.jp/losaul/car-importers-australia.html car importers australia] [http://s1.shard.jp/frhorton/4lte5ty9r.html east and southern african management institute
| |
− | ] [http://s1.shard.jp/galeach/new182.html asian teacher school girl
| |
− | ] [http://s1.shard.jp/frhorton/ndbzagarh.html south africa phone cards italy
| |
− | ]
| |
− | [http://s1.shard.jp/bireba/download-norton.html antivirus free trial download
| |
− | ] [http://s1.shard.jp/losaul/business-services.html australia en estudiar ingles
| |
− | ] [http://s1.shard.jp/olharder/autoroll-654.html webmap] [http://s1.shard.jp/frhorton/vwktsknc4.html exporting cars to south africa
| |
− | ] [http://s1.shard.jp/frhorton/rykfyeh82.html african diaspora journal
| |
− | ] [http://s1.shard.jp/galeach/new118.html i.amasianmen
| |
− | ] [http://s1.shard.jp/olharder/cheat-sheets.html auto rebuilt transmission
| |
− | ] [http://s1.shard.jp/olharder/autoroll-654.html sitemap] [http://s1.shard.jp/olharder/autodesk-inventor.html autopage rs 720lcd review
| |
− | ] [http://s1.shard.jp/losaul/diabetes-australia.html australian universities ranked
| |
− | ] [http://s1.shard.jp/olharder/autoroll-654.html domain] [http://s1.shard.jp/losaul/australian-music.html novatel hotels australia
| |
− | ] [http://s1.shard.jp/galeach/new108.html aldehyde dehydrogenase asians alcohol treatment
| |
− | ] [http://s1.shard.jp/olharder/auto-buy-com.html auto guard car alarm
| |
− | ] [http://s1.shard.jp/olharder/tactical-automated.html shipping boxes for auto glass
| |
− | ] [http://s1.shard.jp/olharder/auto-car-guys.html auto body parts manufacure
| |
− | ] [http://s1.shard.jp/bireba/antivirus-services.html top antivirus for 2005
| |
− | ] [http://s1.shard.jp/bireba/anyware-antivirus.html avg vs avast antivirus
| |
− | ] [http://s1.shard.jp/frhorton/ank33l6la.html kalulu south africa
| |
− | ] [http://s1.shard.jp/losaul/unley-council-south.html australian food industry conference
| |
− | ] [http://s1.shard.jp/olharder/autoroll-654.html http] [http://s1.shard.jp/frhorton/bc7zse5ug.html white south african culture
| |
− | ] [http://s1.shard.jp/bireba/symantec-antivirus.html panda titanium antivirus plus
| |
− | ] [http://s1.shard.jp/losaul/liberal-party.html subaru australia
| |
− | ] [http://s1.shard.jp/galeach/new79.html animals of the asian rainforest
| |
− | ] [http://s1.shard.jp/olharder/autores-romanticos.html autoanything coupon free
| |
− | ] [http://s1.shard.jp/galeach/new111.html asian black hardcore
| |
− | ] [http://s1.shard.jp/olharder/autoroll-654.html page] [http://s1.shard.jp/galeach/new50.html mild dysplasia leep
| |
− | ] [http://s1.shard.jp/losaul/job-agencies-sydney.html deception bay australia
| |
− | ] [http://s1.shard.jp/galeach/new125.html ophthalmic lens in asia
| |
− | ] [http://s1.shard.jp/olharder/wheels-and-deals.html autopilot kota minn motor trolling
| |
− | ] [http://s1.shard.jp/losaul/australian-citizenship.html business sales australia
| |
− | ] [http://s1.shard.jp/galeach/new43.html asian girl hot little
| |
− | ] [http://s1.shard.jp/olharder/audi-automotive.html autovermietung koeln
| |
− | ] [http://s1.shard.jp/galeach/new180.html asian hoe hot] [http://s1.shard.jp/frhorton/4dyaal72j.html african american design hair
| |
− | ] [http://s1.shard.jp/olharder/autoroll-654.html url] [http://s1.shard.jp/frhorton/71w3q2xvj.html africa holiday resort south
| |
− | ] [http://s1.shard.jp/olharder/accessory-automotive.html kruse auto auction
| |
− | ] [http://s1.shard.jp/galeach/new63.html chicago asian singles] [http://s1.shard.jp/losaul/tents-australia.html swann insurance australia
| |
− | ] [http://s1.shard.jp/bireba/symantec-antivirus.html symantec antivirus corporate edition 10.0 2.2000
| |
− | ] [http://s1.shard.jp/frhorton/vjlche4gq.html african congo grey timneh
| |
− | ] [http://s1.shard.jp/bireba/review-antivirus.html norton antivirus 2005 download free
| |
− | ] [http://s1.shard.jp/olharder/autoroll-654.html top] [http://s1.shard.jp/galeach/new130.html asian pusy
| |
− | ] [http://s1.shard.jp/frhorton/3l77ipk2f.html south singapore africa travel advisory
| |
− | ] [http://s1.shard.jp/bireba/avast-free-antivirus.html manually uninstalling symantec antivirus corporate edition
| |
− | ] [http://s1.shard.jp/olharder/automobile-bmw.html grand theft auto san andreas pictures of cars
| |
− | ]
| |
− | http://www.textletoeltd.com
| |
− | [[Image:OWASP_TW_Banner.png]]
| |
| | | |
− | æÃÂáèÿÃÂÃÂ¥ÃÂàÃÂ¥ÃÂ
ÃÂ¥OWASPÃÂ¥ÃÂðçÃÂãÃÂ¥ÃÂÃÂæÃÂÃÂïüÃÂãÃÂÃÂçöòçëÃÂÃ¥îÃÂÃÂ¥ÃÂ
èçÃÂÃÂçììäøÃÂæÃÂÃ¥ïüÃÂÃ¥þÃÂÃÂ¥ÃÂàÃÂ¥ÃÂ
ÃÂ¥OWASPÃÂ¥ÃÂðçÃÂãÃÂ¥ÃÂÃÂæÃÂÃÂéÃÂÃÂÃ¥çÃÂãÃÂÃÂãÃÂÃÂ
| + | {{Chapter Template|chaptername=Taiwan|extra=The chapter leader position is '''OPEN'''. |
| + | |meetupurl=CHANGEME|region=Asia/Pacific/Middle East}} |
| | | |
− | <paypal>Taiwan</paypal>
| + | == Local News == |
| | | |
− | ÃÂ¥ÃÂðçÃÂãÃÂ¥ÃÂÃÂæÃÂÃÂæÃÂÃÂéÃÂ÷[mailto:[email protected] éûÃÂèÃÂÃÂæÃÂÃÂÃÂ¥ÃÂ
ÃÂçÃÂÃÂïüÃÂWayne HuangïüÃÂ]æÃÂèÃÂ¥ÃÂÃÂæÃÂÃÂÃ¥÷Ã¥äýÃÂÃÂ¥ÃÂÃÂäûÃÂèá÷Ã¥ÿÃÂèÃÂïÃ¥îÃÂæÃÂèçÃÂÃÂÃÂ¥ÃÂÃÂèÃÂÃÂïüÃÂäøÃÂçîáæÃÂèÃÂ¥ÃÂèäýÃÂèÃÂÃÂïüÃÂçÃÂÃÂèÃÂóæÃÂèÃÂ¥ÃÂÃÂ
æÃÂþçÃÂÃÂäøÃÂçöòè÷ïèöóè÷áæÃÂüÃÂ¥ÃÂðçÃÂãïüÃÂæÃÂÃÂèìÃÂæÃÂèéáÃÂæÃÂÃÂè÷ÃÂÃ¥äçÃ¥îöäøÃÂèõ÷ÃÂ¥ÃÂÃÂäúëïüÃÂèîÃÂæÃÂÃÂÃÂ¥ÃÂÃÂçÃÂèæÃÂôÃ¥äÃÂäøÃÂÃÂ¥ÃÂÃÂçÃÂÃÂèçÃÂÃ¥úæäþÃÂæêâèæÃÂWebÃ¥îÃÂÃÂ¥ÃÂ
èçÃÂÃÂèöèÃÂ¥ÃÂâãÃÂÃÂÃ¥èÃÂèÃÂÃÂ
ãÃÂÃÂÃÂ¥ÃÂÃÂéáÃÂèÃÂÃÂèçãæñúæÃÂùæáÃÂãÃÂà| + | '''Meeting Location''' |
| | | |
− | == æÃÂáèÿÃÂÃÂ¥ÃÂ
ÃÂèÃÂè OWASP ÃÂ¥ÃÂðçÃÂãÃÂ¥ÃÂÃÂæÃÂà==
| + | Everyone is welcome to join us at our chapter meetings. |
| | | |
− | == æÃÂÃÂæÃÂðæôûÃÂ¥ÃÂà==
| + | [[Category:OWASP Chapter]] |
− | === [[OWASP_AppSec_Asia_2007|çììäøÃÂÃ¥ñÃÂOWASPÃ¥îÃÂæÃÂùäúÃÂæôòÃ¥ùôæÃÂÃÂ(OWASP Asia 2007)]] ===
| |
− | '''Security 3.0 in Web 2.0 Age âÃÂàPractices and Challenges of Web 2.0 Security'''
| |
− | | |
− | [OWASP_AppSec_Asia_2007 http://www.owasp.org/images/f/f7/Owasp_taiwan_2007small.png]
| |
− | | |
− | Whitehat SecurityãÃÂÃÂçþÃÂÃÂ¥ÃÂÃÂéÃÂÃÂéÃÂÃÂ(American Express)ãÃÂÃÂéÃÂÿçâüççÃÂæÃÂÃÂ(Armorize)ãÃÂÃÂQualysçÃÂÃÂè÷èÃÂ¥ÃÂÃÂäüÃÂæÃÂ¥ÃÂèÃÂÃÂèóÃÂÃ¥îÃÂÃÂ¥ÃÂ
ìÃÂ¥ÃÂøçÃÂÃÂéëÃÂéÃÂÃÂäøûçîáèÃÂÃÂéæÃÂÃ¥øÃÂçàÃÂçéöÃÂ¥ÃÂáéýÃÂèÃÂÃÂÃÂ¥ÃÂðçÃÂãïüÃÂæÃÂèçÃÂÃ¥éÃÂÃÂäûÃÂÃÂ¥ÃÂÃÂÃ¥æÃÂäýÃÂçÃÂÃÂÃ¥þÃÂ
Web 2.0æÃÂÃÂäûãäùàSecurity 3.0ÃÂ¥ÃÂÃÂïüÃÂÃ¥ðÃÂÃÂ¥ÃÂðçÃÂãèÃÂÃÂÃÂ¥ÃÂ
èçÃÂÃÂçÃÂÃÂÃÂ¥ÃÂëæÃÂÃÂæÃÂïäûÃÂéúüïüÃÂæÃÂÃÂæÃÂÿÃ¥úÃÂãÃÂÃÂäüÃÂæÃÂ¥ÃÂèÃÂÃÂäøÃÂèÃÂìäýÿçÃÂèèÃÂÃÂ
ÃÂ¥ÃÂÃÂèéòÃ¥æÃÂäýÃÂÃÂ¥ÃÂàæÃÂÃÂïüÃÂÃ¥þÃÂäøÃÂéÃÂâéÃÂÃÂäúÃÂ2007Ã¥ùôçÃÂÃÂèóÃÂÃ¥îÃÂçÃÂÃÂÃ¥äçæÃÂðèÃÂÃÂïüÃÂéÃÂÃÂéÃÂòèÃÂÃÂæÃÂÃÂæèãçÃÂÃÂèèÃÂæÃÂïïüÃÂ
| |
− | * 5æÃÂÃÂ11æÃÂÃ¥èõ÷ïüÃÂGoogleéÃÂÃÂÃ¥çÃÂçÃÂãæÃÂçéÃÂÃÂéçÃÂçöòçëÃÂïüÃÂäøæèòüäøÃÂÃÂ¥ÃÂñéÃÂêçöòçëÃÂäùÃÂæèÃÂçñä!
| |
− | * 5æÃÂÃÂ15æÃÂÃ¥æÃÂÃÂOWASPÃÂ¥ÃÂ
ìäýÃÂ2007Ã¥ùôæÃÂÃÂæÃÂðçÃÂÃÂÃÂ¥ÃÂÃÂÃ¥äçWebÃ¥üñéûÃÂïüÃÂè÷èçëÃÂèÃÂ
óæÃÂìæÃÂûæÃÂÃÂ(XSS)çÃÂûäøÃÂææÃÂéæÃÂ!
| |
− | * 6æÃÂÃÂ6æÃÂÃÂ¥IBMèóüäýõWatchfireïüÃÂHPéÃÂèÃÂ¥ÃÂóæÃÂü6æÃÂÃÂ19æÃÂÃ¥èóüäýõSPI Dynamics!èÃÂÃÂÃÂ¥ÃÂÃÂ
ÃÂ¥ÃÂÃÂçÃÂÃÂCenzicäûÃ¥æûòéÃÂÃÂæøìèéææÃÂÃÂèáÃÂæÃÂü6æÃÂÃÂ18æÃÂÃ¥çÃÂòÃ¥þÃÂçþÃÂÃÂ¥ÃÂÃÂÃ¥ðÃÂÃÂ¥ÃÂé!
| |
− | * Web 2.0çÃÂÃÂèóÃÂÃ¥îÃÂÃ¥èÃÂèÃÂÃÂ
ïüÃÂÃÂ¥ÃÂàæÃÂÃÂäùÃÂéÃÂÃÂïüÃÂSecurity 3.0ïüÃÂæÃÂÃÂÃÂ¥ÃÂÃÂçÃÂÃÂÃ¥ïæÃÂ¥ÃÂÃÂæáÃÂäþÃÂïüÃÂ
| |
− | [[OWASP_AppSec_Asia_2007|çììäøÃÂÃ¥ñÃÂOWASPÃ¥îÃÂæÃÂùäúÃÂæôòÃ¥ùôæÃÂÃÂ]]Ã¥ðÃÂæÃÂü9æÃÂÃÂ27æÃÂÃÂ¥(éÃÂñÃÂ¥ÃÂÃÂ)äøÃÂÃÂ¥ÃÂÃÂ1éûÃÂæÃÂüÃÂ¥ÃÂðÃ¥äçéÃÂëéÃÂâÃÂ¥ÃÂÃÂéÃÂÃÂæÃÂÃÂèÃÂðäøÃÂÃ¥ÿÃÂ201Ã¥îä(ÃÂ¥ÃÂðÃÂ¥ÃÂÃÂÃ¥øÃÂäøÃÂæÃÂãÃÂ¥ÃÂÃÂÃ¥þÃÂÃ¥÷ÃÂè÷ïäúÃÂèÃÂÃÂ)'''èÃÂÃÂèþæïüÃÂæÃÂáèÿÃÂæÃÂèäþÃÂÃÂ¥ÃÂ
ñèÃÂ¥ÃÂçÃÂÃÂèÃÂÃÂïüÃÂæûÿèüÃÂèÃÂÃÂæÃÂø![[OWASP_AppSec_Asia_2007|éÃÂÃÂæÃÂÃÂæÃÂôÃ¥äÃÂ...]]
| |
− | | |
− | === [http://hitcon.org çììäøÃÂÃ¥ñÃÂÃÂ¥ÃÂðçÃÂãéçÃÂÃ¥îâÃ¥ùôæÃÂÃÂ(HIT 2007)] ===
| |
− | | |
− | [http://hitcon.org çììäøÃÂÃ¥ñÃÂÃÂ¥ÃÂðçÃÂãéçÃÂÃ¥îâÃ¥ùôæÃÂÃÂ(HIT 2007)]Ã¥÷òæÃÂü2007Ã¥ùô7æÃÂÃÂ21æÃÂÃÂ¥(éÃÂñÃÂ¥ÃÂ
ÃÂ)èÃÂó22æÃÂÃÂ¥(éÃÂñæÃÂÃÂ¥)ÃÂ¥ÃÂèÃÂ¥ÃÂÃÂçëÃÂèÃÂúçÃÂãççÃÂæÃÂÃÂÃ¥äçÃÂ¥ÃÂøÃÂ¥ÃÂ
ìéäèæàáÃÂ¥ÃÂÃÂÃÂ¥ÃÂÃÂæûÿèÃÂýÃ¥ùÃÂïüÃÂæôûÃÂ¥ÃÂÃÂçÃÂÃÂæóÃÂçéúÃÂ¥ÃÂÃÂïüÃÂèéóæÃÂÃÂ
èëÃÂèæàHIT 2007 Ã¥îÃÂæÃÂùçöòçëÃÂ:
| |
− | [http://hitcon.org http://www.owasp.org/images/b/b5/Owasp_taiwan_HIT-linkLOGO.gif] http://hitcon.org
| |
− | | |
− | == æÃÂáèÿÃÂæÃÂèçÃÂÃÂÃÂ¥ÃÂÃÂèÃÂà==
| |
− | ÃÂ¥ÃÂàÃÂ¥ÃÂ
ÃÂ¥OWASPÃÂ¥ÃÂðçÃÂãÃÂ¥ÃÂÃÂæÃÂÃÂäøÃÂéÃÂÃÂäûûäýÃÂèòûçÃÂèïüÃÂæÃÂÃÂÃÂ¥ÃÂáèóÃÂæàüÃ¥îÃÂÃÂ¥ÃÂ
èéÃÂÃÂæÃÂþçõæäûûäýÃÂÃ¥ðÃÂæÃÂüæÃÂÃÂçÃÂèçèÃÂÃ¥üÃÂÃ¥îÃÂÃÂ¥ÃÂ
èæÃÂÃÂèÃÂÃÂèöãçÃÂÃÂäúúÃ¥ãëïüÃÂ
| |
− | æÃÂÃÂÃÂ¥ÃÂÃÂéüÃÂÃÂ¥ÃÂõæÃÂÃÂÃÂ¥ÃÂáæÃÂüOWASPÃÂ¥ÃÂðçÃÂãÃÂ¥ÃÂÃÂæÃÂÃÂÃÂ¥ÃÂÃÂäúëäûÃÂÃÂ¥ÃÂÃÂçÃÂÃÂçÃÂÃ¥èÃÂÃÂäøææÃÂÃÂäþÃÂÃ¥ðÃÂéáÃÂæüÃÂèìÃÂïüÃÂ
| |
− | èÃÂÃÂÃÂ¥ÃÂèÃÂ¥ÃÂàÃÂ¥ÃÂ
Ã¥æÃÂÃÂÃÂ¥ÃÂáÃÂ¥ÃÂÃÂïüÃÂèëÃÂæÃÂèäûÃÂçôðéÃÂñèîÃÂ[https://www.owasp.org/index.php/Chapter_Rules ÃÂ¥ÃÂÃÂæÃÂÃÂæÃÂÃÂÃÂ¥ÃÂáæÃÂÃÂÃÂ¥ÃÂÃÂ]ãÃÂÃÂ
| |
− | èÃÂÃ¥èæÃÂÃÂ¥ÃÂàÃÂ¥ÃÂ
Ã¥æÃÂìÃÂ¥ÃÂÃÂæÃÂÃÂçÃÂÃÂmailing listïüÃÂèëÃÂéÃÂãçõÃÂÃÂ¥ÃÂð[http://lists.owasp.org/mailman/listinfo/owasp-taiwan mailing list]çöòéàÃÂïüÃÂ
| |
− | æÃÂÃÂæÃÂÃÂçÃÂÃÂæôûÃÂ¥ÃÂÃÂèèÃÂèëÃÂèÃÂÃÂæôûÃÂ¥ÃÂÃÂÃÂ¥ÃÂðéûÃÂÃ¥ðÃÂéÃÂÃÂéÃÂÃÂéÃÂÃÂÃÂ¥ÃÂÃÂæøÃÂ
ÃÂ¥ÃÂîäþÃÂèèÃÂèëÃÂïüÃÂ
| |
− | æÃÂèäùÃÂÃÂ¥ÃÂïäûÃ¥åþÃÂ[http://lists.owasp.org/pipermail/owasp-taiwan/ email èèÃÂèëÃÂÃÂ¥ÃÂÃÂäûý]äøÃÂæÃÂþÃÂ¥ÃÂðæÃÂÃÂÃÂ¥ÃÂÃÂäùÃÂÃÂ¥ÃÂÃÂèèÃÂèëÃÂçÃÂÃÂÃÂ¥ÃÂÃÂäûýãÃÂÃÂ
| |
− | æÃÂÃÂÃ¥þÃÂæÃÂÃÂéÃÂÃÂæÃÂèïüÃÂÃÂ¥ÃÂÃÂÃÂ¥ÃÂàæôûÃÂ¥ÃÂÃÂÃÂ¥ÃÂÃÂïüÃÂèëÃÂÃÂ¥ÃÂÃÂæìáæêâæÃÂÃ¥æÃÂèmailing listçÃÂÃÂäÿáäûöäûÃ¥çâúÃ¥îÃÂæôûÃÂ¥ÃÂÃÂÃÂ¥ÃÂðéûÃÂèÃÂÃÂæÃÂÃÂéÃÂÃÂïüÃÂæÃÂÃÂæÃÂïäûûäýÃÂæÃÂÃÂéÃÂÃÂæôûÃÂ¥ÃÂÃÂèèÃÂéÃÂÃÂçÃÂÃÂäúÃÂéàÃÂ
ãÃÂÃÂ
| |
− | | |
− | == æÃÂÃÂéÃÂÃÂOWASP (About OWASP) ==
| |
− | OWASP(éÃÂÃÂæÃÂþWebèûÃÂéëÃÂÃ¥îÃÂÃÂ¥ÃÂ
èèèÃÂçÃÂë - Open Web Application Security Project)æÃÂïäøÃÂÃÂ¥ÃÂÃÂéÃÂÃÂæÃÂþçäþçþäãÃÂÃÂéÃÂÃÂçÃÂÃÂÃÂ¥ÃÂéæÃÂççõÃÂçùÃÂïüÃÂçÃÂîÃÂ¥ÃÂÃÂÃÂ¥ÃÂ
èçÃÂÃÂæÃÂÃÂ82ÃÂ¥ÃÂÃÂÃÂ¥ÃÂÃÂæÃÂÃÂèÿÃÂèÃÂìÃÂ¥ÃÂÃÂæÃÂÃÂÃÂ¥ÃÂáïüÃÂÃÂ¥ÃÂ
öäøûèæÃÂçÃÂîæèÃÂæÃÂïçàÃÂèÃÂðÃÂ¥ÃÂÃÂÃÂ¥ÃÂéèçãæñúWebèûÃÂéëÃÂÃ¥îÃÂÃÂ¥ÃÂ
èäùÃÂæèÃÂæúÃÂãÃÂÃÂÃ¥÷ÃÂ¥ÃÂ¥ÃÂ
֏ÃÂÃÂæÃÂÃÂèáÃÂæÃÂÃÂäûöïüÃÂéÃÂ־ÃÂÃÂèÃÂôÃÂ¥ÃÂÃÂæÃÂüÃÂ¥ÃÂÃÂÃÂ¥ÃÂéæÃÂÿÃ¥úÃÂæÃÂÃÂäüÃÂæÃÂ¥ÃÂçÃÂÃÂèçãäøææÃÂùÃÂ¥ÃÂÃÂçöòéàÃÂæÃÂÃÂçÃÂèçèÃÂÃ¥üÃÂèÃÂÃÂçöòéàÃÂæÃÂÃÂÃÂ¥ÃÂÃÂçÃÂÃÂÃ¥îÃÂÃÂ¥ÃÂ
èæÃÂçãÃÂÃÂçÃÂñæÃÂüæÃÂÃÂçÃÂèçïÃÂÃÂ¥ÃÂÃÂæÃÂÃ¥åûãïüÃÂçöòéàÃÂæÃÂÃÂçÃÂèÃ¥îÃÂÃÂ¥ÃÂ
èÃ¥÷òçöÃÂéÃÂÃÂæüøçÃÂÃÂÃÂ¥ÃÂÃÂÃÂ¥ÃÂðéÃÂÃÂèæÃÂïüÃÂäøææüøæüøæÃÂÃÂçÃÂúÃÂ¥ÃÂèÃ¥îÃÂÃÂ¥ÃÂ
èéàÃÂÃÂ¥ÃÂÃÂçÃÂÃÂäøÃÂÃÂ¥ÃÂÃÂçÃÂñéÃÂÃÂèéñéáÃÂïüÃÂÃÂ¥ÃÂèæÃÂäÃÂ¥ÃÂÃÂæÃÂÃÂïüÃÂéçÃÂÃ¥îâÃÂ¥ÃÂÃÂäùÃÂæÃÂÃÂæÃÂÃÂçÃÂÃÂÃ¥ðÃÂçÃÂæéûÃÂèýÃÂççûÃÂ¥ÃÂðçöòéàÃÂæÃÂÃÂçÃÂèçèÃÂÃ¥üÃÂéÃÂÃÂçÃÂüæÃÂÃÂæÃÂÃÂæÃÂÃÂçÃÂâçÃÂÃÂçÃÂÃÂÃ¥üñéûÃÂäþÃÂéÃÂòèáÃÂæÃÂûæÃÂÃÂèÃÂÃÂçàôÃ¥ãÃÂãÃÂÃÂ
| |
− | | |
− | çþÃÂÃÂ¥ÃÂÃÂèÃÂïéÃÂæèòÿæÃÂÃÂÃ¥çÃÂÃÂ¥ÃÂáæÃÂÃÂ(FTC)Ã¥ü÷çÃÂÃÂÃ¥ûúèÃÂðæÃÂÃÂæÃÂÃÂäüÃÂæÃÂ¥ÃÂéÃÂÃÂéÃÂõÃ¥þêOWASPæÃÂÃÂçÃÂüäýÃÂçÃÂÃÂÃÂ¥ÃÂÃÂÃ¥äçWebÃ¥üñéûÃÂéÃÂòèÃÂ÷Ã¥îÃÂÃÂ¥ÃÂÃÂãÃÂÃÂçþÃÂÃÂ¥ÃÂÃÂÃÂ¥ÃÂÃÂéÃÂòéÃÂèäúæÃÂ¥ÃÂÃÂçÃÂúæÃÂÃÂäýóÃ¥ïæÃÂ¥ÃÂÃÂïüÃÂÃÂ¥ÃÂÃÂéÃÂÃÂäÿáçÃÂèÃÂ¥ÃÂáèóÃÂæÃÂÃÂÃ¥îÃÂÃÂ¥ÃÂ
èæÃÂÃÂèáÃÂPCIæèÃÂæúÃÂæÃÂôÃ¥ðÃÂÃÂ¥ÃÂ
öÃÂ¥ÃÂÃÂçÃÂúÃ¥ÿÃÂ
èæÃÂÃÂ¥ÃÂ
ÃÂäûöãÃÂÃÂçÃÂîÃÂ¥ÃÂÃÂOWASPæÃÂÃÂ30Ã¥äÃÂÃÂ¥ÃÂÃÂéÃÂòèáÃÂäøÃÂçÃÂÃÂèèÃÂçÃÂëïüÃÂÃÂ¥ÃÂÃÂ
æÃÂìæÃÂÃÂçÃÂÃÂ¥ÃÂ¥ÃÂÃÂçÃÂÃÂOWASP Top 10(ÃÂ¥ÃÂÃÂÃ¥äçWebÃ¥üñéûÃÂ)ãÃÂÃÂWebGoat(äûãçýêçþÃÂçþÃÂ)ç÷ôçÿÃÂÃ¥ùóÃÂ¥ÃÂðãÃÂÃÂÃ¥îÃÂÃÂ¥ÃÂ
èPHP/Java/ASP.NetçÃÂÃÂèèÃÂçÃÂëïüÃÂéÃÂÃÂÃ¥ðÃÂäøÃÂÃÂ¥ÃÂÃÂçÃÂÃÂèûÃÂéëÃÂÃ¥îÃÂÃÂ¥ÃÂ
èÃÂ¥ÃÂÃÂéáÃÂÃÂ¥ÃÂèéÃÂòèáÃÂèèÃÂèëÃÂèÃÂÃÂçàÃÂçéöãÃÂÃÂ
| |
− | | |
− | çÃÂöèòôÃÂ¥ÃÂîäýÃÂæñúÃ¥îÃÂéÃÂÃÂæÃÂþçöòéàÃÂæÃÂÃÂÃÂ¥ÃÂÃÂæÃÂÃÂïüÃÂÃ¥ðñÃ¥ÿÃÂ
éàÃÂèîÃÂäþÃÂèÃÂêæÃÂüÃÂ¥ÃÂ
èçÃÂÃÂçÃÂÃÂçöòéàÃÂèëÃÂæñÃÂéÃÂòÃÂ¥ÃÂ
ÃÂ¥ÃÂ¥ÃÂîäýÃÂÃÂ¥ÃÂ
çéÃÂèçÃÂÃÂçöòéàÃÂäüúæÃÂÃÂÃÂ¥ÃÂèãÃÂÃÂéçÃÂÃ¥îâÃÂ¥ÃÂïäûÃ¥èÃÂÃÂçÃÂñéÃÂñèÃÂÃÂÃÂ¥ÃÂèÃÂ¥ÃÂÃÂæóÃÂçÃÂÃÂçöòéàÃÂèëÃÂæñÃÂÃÂ¥ÃÂ
çïüÃÂéÃÂÃÂéÃÂÃÂéÃÂòçÃÂëçÃÂÃÂãÃÂÃÂÃÂ¥ÃÂ
Ã¥äþõÃÂ¥ÃÂõæøìçóûçõñæÃÂÃÂÃÂ¥ÃÂ
öäûÃÂéÃÂòçææçóûçõñçÃÂÃÂÃÂ¥ÃÂõæøìïüÃÂÃ¥àÃÂèÃÂÃÂçÃÂÃÂäùÃÂçÃÂÃÂéÃÂòÃÂ¥ÃÂ
ÃÂ¥ÃÂ¥ÃÂîäýÃÂÃÂ¥ÃÂ
çéÃÂèæÃÂÃÂèÃÂÃÂçÃÂñÃÂ¥ÃÂîäýÃÂçöòçëÃÂÃÂ¥ÃÂ
ÃÂ
çÃÂöè÷óæÃÂÿèÃÂÃÂäøÃÂçùüçëÃÂèÃÂÃÂÃÂ¥ÃÂÃÂÃÂ¥ÃÂ
öäûÃÂÃÂ¥ÃÂÃÂÃ¥îóèÃÂÃÂ
çÃÂüÃÂ¥ÃÂÃÂæÃÂûæÃÂÃÂãÃÂÃÂéÃÂÃÂæÃÂÃÂÃÂ¥ÃÂóèÃÂÃÂäüÃÂæÃÂ¥ÃÂçÃÂÃÂçöòéàÃÂçèÃÂÃ¥üÃÂçâüäùÃÂÃ¥ÿÃÂ
éàÃÂæÃÂÃÂçÃÂúæéÃÂéÃÂÃÂ(æçÃÂ)ÃÂ¥ÃÂîäýÃÂÃÂ¥ÃÂèéÃÂÃÂçÃÂÃÂÃ¥îÃÂÃÂ¥ÃÂ
èéÃÂòèÃÂ÷äùÃÂäøÃÂïüÃÂçÃÂöÃÂ¥ÃÂîäýÃÂçöòéàÃÂæÃÂÃÂÃÂ¥ÃÂÃÂçÃÂÃÂèæÃÂæèáèÃÂÃÂèäÃÂéÃÂÃÂæÃÂçÃ¥âÃÂÃÂ¥ÃÂàæÃÂÃÂïüÃÂÃÂ¥ÃÂîäýÃÂæÃÂôéÃÂòæÃÂüÃ¥äÃÂçÃÂÃÂéâèéÃÂêäùÃÂéÃÂÃÂæüøÃ¥âÃÂÃÂ¥ÃÂàãÃÂÃÂ
| |
− | | |
− | == OWASP ÃÂ¥ÃÂðçÃÂãÃÂ¥ÃÂÃÂæÃÂà(OWASP Taiwan Chapter) ==
| |
− | *çöòéàÃÂ:http://www.owasp.org.tw
| |
− | | |
− | | |
− | *äýÃÂÃÂ¥ÃÂÃÂ:ÃÂ¥ÃÂðÃÂ¥ÃÂÃÂÃ¥øÃÂ115ÃÂ¥ÃÂÃÂæøïÃÂ¥ÃÂÃÂäøÃÂéÃÂÃÂè÷ï19-13èÃÂÃÂ(ÃÂ¥ÃÂÃÂæøïèûÃÂéëÃÂÃÂ¥ÃÂÃÂÃÂ¥ÃÂÃÂ)EæãÃÂ5æèÃÂ554Ã¥îä
| |
− | | |
− | {{Chapter Template|chaptername=Taiwan|extra=The chapter leader is [mailto:[email protected] Wayne Huang]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-taiwan|emailarchives=http://lists.owasp.org/pipermail/owasp-taiwan}} | |
− | | |
− | Chapter meetings are held several times a year, typically in the offices of our sponsor.
| |
− | | |
− | Please subscribe to the mailing list for meeting announcements.
| |
− | | |
− | == ÃÂ¥ÃÂ
ÃÂèòûÃÂ¥ÃÂàÃÂ¥ÃÂ
ÃÂ¥OWASPÃÂ¥ÃÂðçÃÂãÃÂ¥ÃÂÃÂæÃÂà==
| |
− | | |
− | <font color="#FF0000">
| |
− | | |
− | | |
− | '''ÃÂ¥ÃÂàÃÂ¥ÃÂ
ÃÂ¥OWASPÃÂ¥ÃÂðçÃÂãÃÂ¥ÃÂÃÂæÃÂÃÂäøÃÂéÃÂÃÂäûûäýÃÂèòûçÃÂè'''
| |
− | '''ÃÂ¥ÃÂàÃÂ¥ÃÂ
Ã¥æÃÂÃÂÃÂ¥ÃÂáæÃÂùæóÃÂèëÃÂèæÃÂæÃÂìéàÃÂäøÃÂæÃÂù'''</font> '''[[#Ã¥æÃÂäýÃÂÃÂ¥ÃÂàÃÂ¥ÃÂ
Ã¥æÃÂÃÂÃÂ¥ÃÂá|Ã¥æÃÂäýÃÂÃÂ¥ÃÂàÃÂ¥ÃÂ
Ã¥æÃÂÃÂÃÂ¥ÃÂá]]'''
| |
− | | |
− | ÃÂ¥ÃÂàÃÂ¥ÃÂ
ÃÂ¥OWASPÃÂ¥ÃÂðçÃÂãÃÂ¥ÃÂÃÂæÃÂÃÂäøÃÂéÃÂÃÂäûûäýÃÂèòûçÃÂèïüÃÂæÃÂÃÂÃÂ¥ÃÂáèóÃÂæàüÃ¥îÃÂÃÂ¥ÃÂ
èéÃÂÃÂæÃÂþçõæäûûäýÃÂÃ¥ðÃÂæÃÂüæÃÂÃÂçÃÂèçèÃÂÃ¥üÃÂÃ¥îÃÂÃÂ¥ÃÂ
èæÃÂÃÂèÃÂÃÂèöãçÃÂÃÂäúúÃ¥ãëïüÃÂ<br>
| |
− | æÃÂÃÂÃÂ¥ÃÂÃÂéüÃÂÃÂ¥ÃÂõæÃÂÃÂÃÂ¥ÃÂáæÃÂüOWASPÃÂ¥ÃÂðçÃÂãÃÂ¥ÃÂÃÂæÃÂÃÂÃÂ¥ÃÂÃÂäúëäûÃÂÃÂ¥ÃÂÃÂçÃÂÃÂçÃÂÃ¥èÃÂÃÂäøææÃÂÃÂäþÃÂÃ¥ðÃÂéáÃÂæüÃÂèìÃÂïüÃÂ<br>
| |
− | èÃÂÃÂÃÂ¥ÃÂèÃÂ¥ÃÂàÃÂ¥ÃÂ
Ã¥æÃÂÃÂÃÂ¥ÃÂáÃÂ¥ÃÂÃÂïüÃÂèëÃÂæÃÂèäûÃÂçôðéÃÂñèîÃÂ[https://www.owasp.org/index.php/Chapter_Rules ÃÂ¥ÃÂÃÂæÃÂÃÂæÃÂÃÂÃÂ¥ÃÂáæÃÂÃÂÃÂ¥ÃÂÃÂ]ãÃÂÃÂ
| |
− | | |
− | èÃÂÃ¥èæÃÂÃÂ¥ÃÂàÃÂ¥ÃÂ
Ã¥æÃÂìÃÂ¥ÃÂÃÂæÃÂÃÂçÃÂÃÂmailing listïüÃÂèëÃÂéÃÂãçõÃÂÃÂ¥ÃÂð[http://lists.owasp.org/mailman/listinfo/owasp-taiwan mailing list]çöòéàÃÂïüÃÂ<br>
| |
− | æÃÂÃÂæÃÂÃÂçÃÂÃÂæôûÃÂ¥ÃÂÃÂèèÃÂèëÃÂèÃÂÃÂæôûÃÂ¥ÃÂÃÂÃÂ¥ÃÂðéûÃÂÃ¥ðÃÂéÃÂÃÂéÃÂÃÂéÃÂÃÂÃÂ¥ÃÂÃÂæøÃÂ
ÃÂ¥ÃÂîäþÃÂèèÃÂèëÃÂïüÃÂ<br>
| |
− | æÃÂèäùÃÂÃÂ¥ÃÂïäûÃ¥åþÃÂ[http://lists.owasp.org/pipermail/owasp-taiwan/ email èèÃÂèëÃÂÃÂ¥ÃÂÃÂäûý]äøÃÂæÃÂþÃÂ¥ÃÂðæÃÂÃÂÃÂ¥ÃÂÃÂäùÃÂÃÂ¥ÃÂÃÂèèÃÂèëÃÂçÃÂÃÂÃÂ¥ÃÂÃÂäûýãÃÂÃÂ
| |
− | | |
− | æÃÂÃÂÃ¥þÃÂæÃÂÃÂéÃÂÃÂæÃÂèïüÃÂÃÂ¥ÃÂÃÂÃÂ¥ÃÂàæôûÃÂ¥ÃÂÃÂÃÂ¥ÃÂÃÂïüÃÂèëÃÂÃÂ¥ÃÂÃÂæìáæêâæÃÂÃ¥æÃÂèmailing listçÃÂÃÂäÿáäûöäûÃ¥çâúÃ¥îÃÂæôûÃÂ¥ÃÂÃÂÃÂ¥ÃÂðéûÃÂèÃÂÃÂæÃÂÃÂéÃÂÃÂïüÃÂæÃÂÃÂæÃÂïäûûäýÃÂæÃÂÃÂéÃÂÃÂæôûÃÂ¥ÃÂÃÂèèÃÂéÃÂÃÂçÃÂÃÂäúÃÂéàÃÂ
ãÃÂÃÂ
| |
− | | |
− | == OWASPÃÂ¥ÃÂðçÃÂãÃÂ¥ÃÂÃÂæÃÂàéÃÂèèÃÂýæàü blog ==
| |
− | <font color="#FF0000">éÃÂÃÂèæÃÂäøÃÂæÃÂÃÂèóÃÂÃ¥îÃÂæÃÂÃÂ
Ã¥àñïüÃÂæÃÂÃÂèáÃÂÃÂ¥ÃÂÃÂæÃÂÃÂïüÃÂÃ¥øÃÂÃ¥àôèóÃÂèèÃÂÃÂ¥ÃÂÃÂïüÃÂ
| |
− | | |
− | æÃÂáèÿÃÂÃ¥øøäþà[http://www.owasp.org.tw/blog OWASPÃÂ¥ÃÂðçÃÂãÃÂ¥ÃÂÃÂæÃÂàéÃÂèèÃÂýæàü blog]
| |
− | | |
− | [http://www.owasp.org.tw/blog http://www.owasp.org/images/d/da/OWASP_Banner_Blog.png]
| |
− | </font>
| |
− | | |
− | == Ã¥æÃÂäýÃÂÃÂ¥ÃÂàÃÂ¥ÃÂ
Ã¥æÃÂÃÂÃÂ¥ÃÂá ==
| |
− | æÃÂáèÿÃÂÃÂ¥ÃÂ
ÃÂèòûÃÂ¥ÃÂàÃÂ¥ÃÂ
ÃÂ¥OWASP TaiwanÃÂ¥ÃÂðçÃÂãÃÂ¥ÃÂÃÂæÃÂÃÂïüÃÂÃÂ¥ÃÂàÃÂ¥ÃÂ
Ã¥æÃÂùÃ¥üÃÂæÃÂÃÂäøÃÂçèîïüÃÂç÷ÃÂäøÃÂÃ¥àñÃÂ¥ÃÂÃÂïüÃÂemailÃ¥àñÃÂ¥ÃÂÃÂäûÃÂ¥ÃÂ¥ÃÂÃÂÃÂ¥ÃÂóçÃÂÃÂÃ¥àñÃÂ¥ÃÂÃÂïüÃÂ
| |
− | Ã¥÷Ã¥äýÃÂÃÂ¥ÃÂÃÂäûÃÂæÃÂÃÂæÃÂÃÂçúÃÂéÃÂÃÂçÃÂÃ¥æÃÂÃÂæÃÂÃÂæÃÂÃÂÃÂ¥ÃÂáæÃÂÃÂéÃÂÃÂOWASPæÃÂÃÂæÃÂðæôûÃÂ¥ÃÂÃÂèóÃÂèèÃÂèÃÂÃÂÃ¥úçèëÃÂæÃÂÃÂèÃÂðçèÃÂ.
| |
− | | |
− | | |
− | === ç÷ÃÂäøÃÂÃ¥àñÃÂ¥ÃÂà===
| |
− | èëÃÂ[http://www.owasp.org.tw/member/registration.php æÃÂÃÂæÃÂäÃ¥áëÃ¥ïëç÷ÃÂäøÃÂÃ¥àñÃÂ¥ÃÂÃÂÃÂ¥ÃÂî]
| |
− | | |
− | === EmailÃ¥àñÃÂ¥ÃÂà===
| |
− | èëÃÂemailïüÃÂ[mailto:[email protected] [email protected]]ÃÂ¥ÃÂàÃÂ¥ÃÂ
ÃÂ¥ÃÂ¥ÃÂðçÃÂãÃÂ¥ÃÂÃÂæÃÂÃÂ,èëÃÂèèûæÃÂÃÂäøÃÂÃÂ¥ÃÂÃÂèóÃÂèèÃÂ. | |
− | #Ã¥çÃÂÃÂ¥ÃÂÃÂ
| |
− | #ÃÂ¥ÃÂîäýÃÂ
| |
− | #èÃÂ÷çèñ
| |
− | #éÃÂûÃÂ¥ÃÂÃÂéÃÂõäûö
| |
− | #èÃÂïçõáéÃÂûèéñ
| |
− | | |
− | === ÃÂ¥ÃÂóçÃÂÃÂÃ¥àñÃÂ¥ÃÂà===
| |
− | èëÃÂÃÂ¥ÃÂÃÂÃÂ¥ÃÂðæÃÂäÃ¥àñÃÂ¥ÃÂÃÂèáè,Ã¥áëÃ¥ïëÃ¥þÃÂÃÂ¥ÃÂóçÃÂÃÂèÃÂó(02)6616-1100ÃÂ¥ÃÂóÃÂ¥ÃÂï.
| |
− | | |
− | [[Image:owasp_taiwan_opening.jpg|800px]]
| |
− | | |
− | == èÿÃÂæÃÂÃÂæöÃÂæÃÂï ==
| |
− | | |
− | *WebæÃÂÃÂçÃÂèçèÃÂÃ¥üÃÂÃ¥îÃÂÃÂ¥ÃÂ
èçàÃÂèèÃÂæÃÂÃÂ:ÃÂ¥ÃÂè2008Ã¥ùô7æÃÂÃÂ22æÃÂÃ¥èõ÷ïüÃÂèáÃÂæÃÂÿéÃÂâçàÃÂèÃÂÃÂæÃÂÃÂèÃÂÃÂèóÃÂéÃÂÃÂÃ¥îÃÂÃÂ¥ÃÂ
èæÃÂÃÂÃ¥àñæÃÂÃÂæÃÂÃÂäøÃÂÃ¥ÿÃÂèÃÂÃÂèþæäùÃÂ[http://www.icst.org.tw/content/application/icst2005/a1001001100110151/guest-cnt-browse.php?var=0,1001,111,100100110017,3353,plan&PHPSESSID=d4815b38629332871cf75bb829fd5546 æÃÂÿÃ¥úÃÂæéÃÂéÃÂÃÂèûÃÂéëÃÂÃ¥îÃÂÃÂ¥ÃÂ
èæÃÂÃÂèáÃÂçàÃÂèèÃÂæÃÂÃÂ]ïüÃÂéÃÂÃÂéÃÂÃÂWeb æÃÂÃÂçÃÂèçèÃÂÃ¥üÃÂÃ¥îÃÂÃÂ¥ÃÂ
èÃÂ¥ÃÂÃÂèÃÂÃÂæÃÂÃÂÃ¥üÃÂÃ¥ðÃÂÃÂ¥ÃÂ
Ã¥æáÃÂäþÃÂïüÃÂçÃÂÃÂèçãWebæÃÂÃÂçÃÂèçèÃÂÃ¥üÃÂÃÂ¥ÃÂïèÃÂýÃ¥üñéûÃÂïüÃÂæÃÂÃÂäþÃÂÃÂ¥ÃÂÃÂæéÃÂéÃÂÃÂ(æçÃÂ)Ã¥çÃÂÃ¥äÃÂçîáçÃÂÃÂÃÂ¥ÃÂÃÂèÃÂÃÂãÃÂÃÂ
| |
− | | |
− | *WebÃ¥îÃÂÃÂ¥ÃÂ
èæÃÂðèÃÂÃÂ:ÃÂ¥ÃÂè2007Ã¥ùô6æÃÂÃÂ11æÃÂÃ¥ïüÃÂiThomeÃ¥àñÃ¥ðÃÂãÃÂÃÂ[http://www.ithome.com.tw/itadm/article.php?c=43813 çöòçëÃÂÃ¥îÃÂÃÂ¥ÃÂ
èæýðÃ¥àäïüÃÂäøÃÂÃ¥îÃÂÃÂ¥ÃÂ
èÃ¥ðñæòÃÂéáçÃ¥îâ]ãÃÂÃÂïüÃÂæ÷ñÃÂ¥ÃÂ
Ã¥èÿýèùäGoogleæÃÂÃÂÃ¥ðÃÂÃ¥üÃÂæÃÂÃÂÃÂ¥ÃÂàæÃÂÃÂæÃÂáæÃÂÃÂçöòçëÃÂäùÃÂæÃÂðæÃÂêæÃÂýïüÃÂÃÂ¥ÃÂ
öæÃÂÃÂÃ¥ðÃÂçõÃÂæÃÂÃÂæÃÂÃÂçÃÂúæÃÂÃÂèóÃÂÃ¥îÃÂÃÂ¥ÃÂÃÂéáÃÂçÃÂÃÂçöòçëÃÂèòüäøÃÂèÃÂæÃÂ¥ÃÂÃÂæèÃÂçñäïüÃÂäøæéÃÂûæÃÂâäýÿçÃÂèèÃÂÃÂ
çÃÂôæÃÂÃ¥çÃÂÃÂèæýãÃÂÃÂ
| |
− | | |
− | *OWASPÃÂ¥ÃÂðçÃÂãÃÂ¥ÃÂÃÂæÃÂÃÂÃÂ¥ÃÂÃÂÃ¥ñÃÂ:ÃÂ¥ÃÂè2007Ã¥ùô4æÃÂÃÂ16èÃÂó18æÃÂÃ¥ïüÃÂÃÂ¥ÃÂðÃÂ¥ÃÂÃÂÃÂ¥ÃÂÃÂéÃÂÃÂèóÃÂÃ¥îÃÂÃ¥ñÃÂ(http://www.secutech.com/tw/is/index.asp) éÃÂÃÂéÃÂÃÂçÃÂûÃ¥àôïüÃÂOWASPÃÂ¥ÃÂðçÃÂãÃÂ¥ÃÂÃÂæÃÂÃÂéÃÂÃÂæÃÂèèÃÂÃÂèÃÂèæÃÂääýÃÂA402èÃÂÃÂA404ïüÃÂÃÂ¥ÃÂóÃÂ¥ÃÂïçÃÂòÃ¥þÃÂWebèóÃÂÃ¥îÃÂÃÂ¥ÃÂ
ÃÂçâÃÂäøÃÂÃ¥üõïüÃÂäøæèæêèÃÂêÃÂ¥ÃÂÃÂæÃÂÃÂéëÃÂééÃÂæïÃÂæûòéÃÂÃÂæøìèéæãÃÂÃÂÃ¥üñéûÃÂçèýæàøçÃÂÃÂÃÂ¥ÃÂóçõñèóÃÂÃ¥îÃÂæêâæøìæÃÂùÃ¥üÃÂæÃÂôçÃÂúÃÂ¥ÃÂêçÃÂðçÃÂÃÂèÃÂêÃÂ¥ÃÂÃÂæúÃÂçâüæêâæøìæÃÂÃÂèáÃÂãÃÂÃÂ
| |
− | | |
− | *WebÃ¥îÃÂÃÂ¥ÃÂ
èæÃÂðèÃÂÃÂ:ÃÂ¥ÃÂè2007Ã¥ùô4æÃÂÃÂ11æÃÂÃ¥ïüÃÂiThomeÃ¥àñÃ¥ðÃÂãÃÂÃÂ[http://www.ithome.com.tw/itadm/article.php?c=42866 OWASPÃÂ¥ÃÂðçÃÂãÃÂ¥ÃÂÃÂæÃÂÃÂæÃÂÃÂçëÃÂæÃÂÃÂÃÂ¥ÃÂáÃÂ¥ÃÂ
ÃÂèòûæÃÂÃÂÃÂ¥ÃÂÃÂäøÃÂïüÃÂçÃÂüÃÂ¥ÃÂéæÃÂÃÂÃÂ¥ÃÂÃÂWebÃ¥îÃÂÃÂ¥ÃÂ
èéÃÂòèÃÂ÷è÷ÃÂäøÃÂÃÂ¥ÃÂÃÂéÃÂÃÂèöèÃÂ¥ÃÂâ]ãÃÂÃÂãÃÂÃÂ
| |
− | | |
− | *WebÃ¥îÃÂÃÂ¥ÃÂ
èæÃÂðèÃÂÃÂ:ÃÂ¥ÃÂè2007Ã¥ùô4æÃÂÃÂ9æÃÂÃ¥ïüÃÂèÃÂÃÂæÃÂÃÂæÃÂÃ¥åàñÃ¥àñÃ¥ðÃÂÃÂ¥ÃÂðçÃÂãÃ¥÷òæÃÂÃÂESPNéëÃÂèÃÂòÃÂ¥ÃÂðçÃÂÃÂèèñÃ¥äÃÂèÃÂÃÂæðÃÂçÃÂþçÃÂÃÂæôûæÃÂïæÃÂïçÃÂøéÃÂÃÂçÃÂÃÂäúÃÂÃÂ¥ÃÂÃÂäøÃÂÃÂ¥ÃÂÃÂÃ¥îÃÂçöòïüÃÂäøÃÂæÃÂÃÂäûÃ¥äþÃÂéÃÂøçúÃÂéÃÂÃÂéçÃÂÃ¥îâæäÃÂÃÂ¥ÃÂ
Ã¥æÃÂèéæìÃ¥þÃÂéÃÂÃÂïüÃÂèÃÂÃÂçÃÂñèûÃÂéëÃÂÃ¥ûàÃÂ¥ÃÂÃÂÃ¥ðÃÂçÃÂáäÿîèãÃÂçèÃÂÃ¥üÃÂçÃÂÃÂãÃÂÃÂéÃÂöæÃÂÃÂÃ¥÷îæÃÂûæÃÂÃÂãÃÂÃÂïüÃÂZero-Day AttackïüÃÂïüÃÂçÃÂáèþÃÂäýÿçÃÂèèÃÂÃÂ
ÃÂ¥ÃÂêèæÃÂéÃÂãäøÃÂçöòçÃÂÃÂèæýïüÃÂéÃÂûèÃÂ
æÃ¥ðñäøÃÂçÃÂÃÂïüÃÂèüÃÂèÃÂÃÂ
Ã¥øóèÃÂÃÂãÃÂÃÂÃ¥ïÃÂçâüéÃÂÃÂçëÃÂïüÃÂèúëÃÂ¥ÃÂÃÂèâëçÃÂÃÂçÃÂèïüÃÂéÃÂÃÂèÃÂÃÂ
æéÃÂæÃÂÃÂèóÃÂæÃÂÃÂÃ¥äÃÂæôéæÃÂÃÂèòáçÃÂéæÃÂÃÂÃ¥äñãÃÂÃÂ
| |
− | | |
− | *WebæÃÂÃÂçÃÂèçèÃÂÃ¥üÃÂÃ¥îÃÂÃÂ¥ÃÂ
èçàÃÂèèÃÂæÃÂÃÂ:ÃÂ¥ÃÂè2007Ã¥ùô3æÃÂÃÂ27èÃÂó4æÃÂÃÂ11æÃÂÃ¥ïüÃÂèáÃÂæÃÂÿéÃÂâçàÃÂèÃÂÃÂæÃÂÃÂèÃÂÃÂèóÃÂéÃÂÃÂÃ¥îÃÂÃÂ¥ÃÂ
èæÃÂÃÂÃ¥àñæÃÂÃÂæÃÂÃÂäøÃÂÃ¥ÿÃÂèÃÂÃÂèþæäùÃÂ[http://sid.iii.org.tw/96Q1_ISMS/ æÃÂÿÃ¥úÃÂèóÃÂéÃÂÃÂÃ¥îÃÂÃÂ¥ÃÂ
èéÃÂòèÃÂ÷Ã¥÷áèÿôçàÃÂèèÃÂæÃÂÃÂïüÃÂèóÃÂÃ¥îÃÂçÃÂüÃ¥ñÃÂèöèÃÂ¥ÃÂâÃÂ¥ÃÂÃÂçöòè÷ïæÃÂÃÂçÃÂèæÃÂÃÂÃÂ¥ÃÂÃÂèóÃÂèèÃÂÃ¥îÃÂÃÂ¥ÃÂ
è]ïüÃÂæÃÂáèÿÃÂæÃÂÿÃ¥úÃÂæéÃÂéÃÂÃÂ(æçÃÂ)èòàèòìèóÃÂéÃÂÃÂÃ¥îÃÂÃÂ¥ÃÂ
èçÃÂøéÃÂÃÂäúúÃÂ¥ÃÂáèøôèúÃÂÃÂ¥ÃÂÃÂÃÂ¥ÃÂàãÃÂÃÂNEW![https://www.owasp.org/images/b/b1/%E5%B7%A1%E8%BF%B4%E7%A0%94%E8%A8%8E%E6%9C%83%E8%AC%9B%E7%BE%A9_Web.pdf çàÃÂèèÃÂæÃÂÃÂèìÃÂçþéäøÃÂèüÃÂ]
| |
− | | |
− | *WebÃ¥îÃÂÃÂ¥ÃÂ
èæÃÂðèÃÂÃÂ:ÃÂ¥ÃÂè2007Ã¥ùô3æÃÂÃÂ21æÃÂÃ¥ïüÃÂäøÃÂÃÂ¥ÃÂÃÂæÃÂÃÂÃ¥àñÃ¥àñÃ¥ðÃÂãÃÂÃÂäøÃÂçöòæÃÂÃÂäøÃÂÃ¥îÃÂÃÂ¥ÃÂ
èÃÂ¥ÃÂÃÂÃ¥îöïüÃÂÃÂ¥ÃÂðçÃÂãéëÃÂÃ¥ñÃÂ
çììäúÃÂãÃÂÃÂïüÃÂçÃÂñæóÃÂÃÂ¥ÃÂÃÂéÃÂèèêÿæÃÂÃ¥åñÃÂãÃÂÃÂÃÂ¥ÃÂÃÂäúÃÂÃ¥ñÃÂçÃÂÃÂÃÂ¥ÃÂîäýÃÂÃÂ¥ÃÂ
ñÃÂ¥ÃÂÃÂéÃÂÃÂÃ¥ðÃÂÃÂ¥ÃÂðçÃÂãçöòè÷ïÃ¥îÃÂÃÂ¥ÃÂ
èéÃÂòèáÃÂèçÃÂÃ¥ïÃÂçÃÂüçÃÂþïüÃÂÃÂ¥ÃÂðçÃÂãçöòè÷ïçÃÂÃÂèóÃÂèèÃÂÃ¥îÃÂÃÂ¥ÃÂ
èÃ¥èÃÂèÃÂÃÂ
ïüÃÂéëÃÂÃ¥ñÃÂ
äúÃÂæôòçììäúÃÂïüÃÂÃÂ¥ÃÂÃÂ
æìáæÃÂüäøÃÂÃÂ¥ÃÂÃÂãÃÂÃÂ2007Ã¥ùôÃÂ¥ÃÂÃÂèÃÂóäûÃÂïüÃÂÃ¥ùóÃÂ¥ÃÂÃÂæïÃÂÃ¥äééÃÂýæÃÂÃÂçÃÂüçÃÂÃÂ5äûöéçÃÂÃ¥îâÃÂ¥ÃÂ
Ã¥äþõäúÃÂäûöãÃÂÃÂ
| |
− | | |
− | *WebÃ¥îÃÂÃÂ¥ÃÂ
èæÃÂðèÃÂÃÂ:ÃÂ¥ÃÂè2007Ã¥ùô3æÃÂÃÂ8æÃÂÃ¥ïüÃÂæÃÂñæãîæÃÂðèÃÂÃÂÃ¥àñÃ¥ðÃÂãÃÂÃÂÃÂ¥ÃÂðçÃÂãéçÃÂÃ¥îâæÃÂûæÃÂÃÂäúÃÂäûöÃÂ¥ÃÂÃÂÃ¥ðÃÂéþÃÂäùÃÂÃÂ¥ÃÂàïüÃÂ90ïüÃÂ
éÃÂÃÂèáÃÂæÃÂþéÃÂÃÂÃÂ¥ÃÂ
Ã¥äþõãÃÂÃÂïüÃÂçÃÂöèÃÂÃÂèèñÃ¥äÃÂäüÃÂæÃÂ¥ÃÂéÃÂýäûÃ¥æòÃÂæÃÂÃÂéàÃÂçîÃÂçÃÂúçÃÂñïüÃÂäøÃÂéáÃÂæÃÂÃÂÃ¥âÃÂÃÂ¥ÃÂàéÃÂòèÃÂ÷èèÃÂÃÂ¥ÃÂÃÂèÃÂÃÂäúúÃÂ¥ÃÂÃÂïüÃÂèâëéçÃÂÃ¥îâçëÃÂæÃÂùÃÂ¥ÃÂ
Ã¥äþõçöòéàÃÂïüÃÂäøÃÂçÃÂÃÂèçãèÃÂÃÂÃ¥þÃÂÃÂ¥ÃÂôéÃÂÃÂçÃÂÃÂæÃÂÃÂçþéïüÃÂçöòéàÃÂæÃÂùÃÂ¥ÃÂÃÂÃ¥þÃÂïüÃÂäøææòÃÂæÃÂÃÂÃ¥âÃÂÃÂ¥ÃÂàéÃÂòèÃÂ÷èèÃÂÃÂ¥ÃÂÃÂïüÃÂçÃÂÃÂèÃÂóéÃÂÃÂæÃÂÃÂÃÂ¥ÃÂîäøÃÂäüÃÂæÃÂ¥ÃÂèâëéçÃÂéÃÂãçúÃÂéëÃÂéÃÂÃÂ82æìáãÃÂÃÂ[http://www.ettoday.com/2007/03/08/339-2063921.htm ÃÂ¥ÃÂÃÂæÃÂðèÃÂÃÂéÃÂãçõÃÂ]
| |
− | | |
− | | |
− | | |
− | [[Image:Owasp taiwan first gathering.png]]
| |
− | | |
− | == çöòçëÃÂèÃÂÃÂWebæÃÂÃÂÃÂ¥ÃÂÃÂçÃÂÃÂäúÃÂÃ¥äçèóÃÂÃ¥îÃÂÃÂ¥ÃÂðÃ¥âà==
| |
− | #ITäúúÃÂ¥ÃÂáäøÃÂèöó
| |
− | #çüúäùÃÂèóÃÂÃ¥îÃÂéàÃÂÃÂ¥ÃÂÃÂÃ¥ðÃÂæÃÂ¥ÃÂçÃÂÃ¥èÃÂÃÂ
| |
− | #ÃÂ¥ÃÂÃÂèÃÂýæÃÂçééÃÂæÃÂöçÃÂúäøû
| |
− | #çüúäùÃÂèÃÂêÃÂ¥ÃÂÃÂÃÂ¥ÃÂÃÂÃ¥÷ÃÂ¥ÃÂ¥ÃÂ
÷
| |
− | #æÃÂÃÂæÃÂìãÃÂÃÂæÃÂÃÂçÃÂÃÂÃ¥ðÃÂÃÂ¥ÃÂÃÂÃ¥ðÃÂæáÃÂæèáÃ¥üÃÂäøÃÂÃÂ¥ÃÂéçâúäÿÃÂÃ¥ðÃÂæáÃÂÃÂ¥ÃÂÃÂèóê
| |
− | | |
− | ==æÃÂÃÂæÃÂð2007Ã¥ùôOWASPÃÂ¥ÃÂÃÂÃ¥äçWebèóÃÂÃ¥îÃÂæüÃÂæôà(2007 OWASP Top 10)==
| |
− | ===ÃÂ¥ÃÂÃÂÃ¥äçWebèóÃÂÃ¥îÃÂæüÃÂæôÃÂÃÂ¥ÃÂÃÂèáè===
| |
− | *A1. è÷èçöòçëÃÂçÃÂÃÂÃÂ¥ÃÂ
Ã¥äþõÃÂ¥ÃÂÃÂäøò(Cross Site ScriptingïüÃÂçðáçèñXSSïüÃÂäúæçèñçÃÂúè÷èçëÃÂèÃÂ
óæÃÂìæÃÂûæÃÂÃÂ)ïüÃÂWebæÃÂÃÂçÃÂèçèÃÂÃ¥üÃÂçÃÂôæÃÂÃ¥åðÃÂäþÃÂèÃÂêäýÿçÃÂèèÃÂÃÂ
çÃÂÃÂÃÂ¥ÃÂ÷èáÃÂèëÃÂæñÃÂéÃÂÃÂÃÂ¥ÃÂÃÂçÃÂÃÂèæýÃÂ¥ÃÂèÃÂ¥ÃÂ÷èáÃÂïüÃÂäýÿÃ¥þÃÂæÃÂûæÃÂÃÂèÃÂÃÂ
ÃÂ¥ÃÂïæÃÂ÷ÃÂ¥ÃÂÃÂäýÿçÃÂèèÃÂÃÂ
çÃÂÃÂCookieæÃÂÃÂSessionèóÃÂæÃÂÃÂèÃÂÃÂèÃÂýÃÂ¥ÃÂÃÂÃÂ¥ÃÂÃÂçÃÂôæÃÂÃ¥çÃÂûÃÂ¥ÃÂ
Ã¥çÃÂúÃÂ¥ÃÂÃÂæóÃÂäýÿçÃÂèèÃÂÃÂ
ãÃÂÃÂ
| |
− | *A2. æóèÃÂ¥ÃÂ
Ã¥çüúÃ¥äñ(Injection Flaw)ïüÃÂWebæÃÂÃÂçÃÂèçèÃÂÃ¥üÃÂÃÂ¥ÃÂ÷èáÃÂäþÃÂèÃÂêÃ¥äÃÂéÃÂèÃÂ¥ÃÂÃÂ
æÃÂìèóÃÂæÃÂÃÂÃ¥úëÃÂ¥ÃÂèÃÂ¥ÃÂ
ççÃÂÃÂæÃÂáæÃÂÃÂæÃÂÃÂäûäïüÃÂSQL InjectionèÃÂÃÂCommand InjectionçÃÂÃÂæÃÂûæÃÂÃÂÃÂ¥ÃÂÃÂ
æÃÂìÃÂ¥ÃÂèÃÂ¥ÃÂ
çãÃÂÃÂ
| |
− | *A3. æÃÂáæÃÂÃÂæêÃÂæáÃÂÃÂ¥ÃÂ÷èáÃÂ(Malicious File Execution)ïüÃÂWebæÃÂÃÂçÃÂèçèÃÂÃ¥üÃÂÃ¥üÃÂÃÂ¥ÃÂ
Ã¥äþÃÂèÃÂêÃ¥äÃÂéÃÂèçÃÂÃÂæÃÂáæÃÂÃÂæêÃÂæáÃÂäøæÃÂ¥ÃÂ÷èáÃÂæêÃÂæáÃÂÃÂ¥ÃÂ
çÃ¥îùãÃÂÃÂ
| |
− | *A4. äøÃÂÃ¥îÃÂÃÂ¥ÃÂ
èçÃÂÃÂçÃÂéäûöÃÂ¥ÃÂÃÂèÃÂÃÂ(Insecure Direct Object Reference)ïüÃÂæÃÂûæÃÂÃÂèÃÂÃÂ
ÃÂ¥ÃÂéçÃÂèWebæÃÂÃÂçÃÂèçèÃÂÃ¥üÃÂæÃÂìèúëçÃÂÃÂæêÃÂæáÃÂèîÃÂÃÂ¥ÃÂÃÂÃÂ¥ÃÂÃÂèÃÂýäûûæÃÂÃÂÃÂ¥ÃÂÃÂÃÂ¥ÃÂÃÂæêÃÂæáÃÂæÃÂÃÂéÃÂÃÂèæÃÂèóÃÂæÃÂÃÂïüÃÂæáÃÂäþÃÂÃÂ¥ÃÂÃÂ
æÃÂìhttp://example/read.php?file=../../../../../../../c:\boot.iniãÃÂÃÂ
| |
− | *A5. è÷èçöòçëÃÂçÃÂÃÂÃÂ¥ÃÂýéÃÂàèæÃÂæñà(Cross-Site Request ForgeryïüÃÂçðáçèñCSRF): Ã¥÷òçÃÂûÃÂ¥ÃÂ
ÃÂ¥WebæÃÂÃÂçÃÂèçèÃÂÃ¥üÃÂçÃÂÃÂÃÂ¥ÃÂÃÂæóÃÂäýÿçÃÂèèÃÂÃÂ
ÃÂ¥ÃÂ÷èáÃÂÃÂ¥ÃÂðæÃÂáæÃÂÃÂçÃÂÃÂHTTPæÃÂÃÂäûäïüÃÂäýÃÂWebæÃÂÃÂçÃÂèçèÃÂÃ¥üÃÂÃÂ¥ÃÂûçÃÂöæÃÂÃÂÃÂ¥ÃÂÃÂæóÃÂéÃÂÃÂæñÃÂèÃÂÃÂçÃÂÃÂïüÃÂäýÿÃ¥þÃÂæÃÂáæÃÂÃÂæÃÂÃÂäûäèâëæÃÂãÃ¥øøÃÂ¥ÃÂ÷èáÃÂïüÃÂæáÃÂäþÃÂÃÂ¥ÃÂÃÂ
æÃÂìçäþäúäçöòçëÃÂÃÂ¥ÃÂÃÂäúëçÃÂàQuickTimeãÃÂÃÂFlashÃ¥ýñçÃÂÃÂäøÃÂèÃÂÃÂæÃÂÃÂæÃÂáæÃÂÃÂçÃÂÃÂHTTPèëÃÂæñÃÂãÃÂÃÂ
| |
− | *A6. èóÃÂèèÃÂæÃÂÃÂéÃÂòèÃÂÃÂäøÃÂéÃÂéçÃÂöéÃÂïèêäèÃÂÃÂçýî (Information Leakage and Improper Error Handling)ïüÃÂWebæÃÂÃÂçÃÂèçèÃÂÃ¥üÃÂçÃÂÃÂÃÂ¥ÃÂ÷èáÃÂéÃÂïèêäèèÃÂæÃÂïÃÂ¥ÃÂÃÂ
ÃÂ¥ÃÂëæÃÂÃÂæÃÂÃÂèóÃÂæÃÂÃÂïüÃÂæáÃÂäþÃÂÃÂ¥ÃÂÃÂ
æÃÂì:çóûçõñæêÃÂæáÃÂè÷ïÃ¥þÃÂçÃÂÃÂæÃÂÃÂéÃÂòæÃÂÃÂèóÃÂæÃÂÃÂÃ¥úëæìÃÂäýÃÂÃÂ¥ÃÂÃÂçèñãÃÂÃÂ
| |
− | *A7. éÃÂÃÂçàôÃ¥ãÃÂçÃÂÃÂéÃÂÃÂÃÂ¥ÃÂÃ¥èÃÂÃÂéÃÂãç÷ÃÂçîáçÃÂÃÂ(Broken Authentication and Session Management)ïüÃÂWebæÃÂÃÂçÃÂèçèÃÂÃ¥üÃÂäøÃÂèÃÂêèáÃÂæÃÂðÃ¥ïëçÃÂÃÂèúëÃÂ¥ÃÂÃÂééÃÂèÃÂÃÂçÃÂøéÃÂÃÂÃÂ¥ÃÂÃÂèÃÂýæÃÂÃÂçüúéÃÂ֋ÃÂÃÂ
| |
− | *A8. äøÃÂÃ¥îÃÂÃÂ¥ÃÂ
èçÃÂÃÂÃ¥ïÃÂçâüÃÂ¥ÃÂòÃÂ¥ÃÂÃÂÃÂ¥ÃÂè (Insecure Cryptographic Storage)ïüÃÂWebæÃÂÃÂçÃÂèçèÃÂÃ¥üÃÂæòÃÂæÃÂÃÂÃ¥ðÃÂæÃÂÃÂæÃÂÃÂæÃÂçèóÃÂæÃÂÃÂäýÿçÃÂèÃÂ¥ÃÂàÃ¥ïÃÂãÃÂÃÂäýÿçÃÂèèüÃÂÃ¥üñçÃÂÃÂÃÂ¥ÃÂàÃ¥ïÃÂæüÃÂçîÃÂæóÃÂæÃÂÃÂÃ¥ðÃÂéÃÂÃÂéÃÂðÃÂ¥ÃÂòÃÂ¥ÃÂÃÂæÃÂüÃ¥îùæÃÂÃÂèâëÃÂ¥ÃÂÃÂÃ¥þÃÂäùÃÂèÃÂÃÂãÃÂÃÂ
| |
− | *A9. äøÃÂÃ¥îÃÂÃÂ¥ÃÂ
èçÃÂÃÂéÃÂÃÂèèÃÂ(Insecure Communication)ïüÃÂÃÂ¥ÃÂóéÃÂÃÂæÃÂÃÂæÃÂÃÂæÃÂçèóÃÂæÃÂÃÂæÃÂÃÂäøææÃÂêäýÿçÃÂèHTTPSæÃÂÃÂÃÂ¥ÃÂ
öäûÃÂÃÂ¥ÃÂàÃ¥ïÃÂæÃÂùÃ¥üÃÂãÃÂÃÂ
| |
− | *A10. çÃÂÃÂæÃÂüéÃÂÃÂÃÂ¥ÃÂöURLÃÂ¥ÃÂÃÂÃÂ¥ÃÂÃÂ(Failure to Restrict URL Access)ïüÃÂæÃÂÃÂäúÃÂçöòéàÃÂÃÂ¥ÃÂàçÃÂúæòÃÂæÃÂÃÂæìÃÂéÃÂÃÂæÃÂçÃÂ¥ÃÂöïüÃÂäýÿÃ¥þÃÂæÃÂûæÃÂÃÂèÃÂÃÂ
ÃÂ¥ÃÂïéÃÂÃÂéÃÂÃÂçöòÃÂ¥ÃÂÃÂçÃÂôæÃÂÃÂ¥ÃÂ¥ÃÂÃÂÃÂ¥ÃÂÃÂïüÃÂæáÃÂäþÃÂÃÂ¥ÃÂÃÂ
æÃÂìÃÂ¥ÃÂ
ÃÂèèñçÃÂôæÃÂÃ¥äÿîæÃÂùWikiæÃÂÃÂBlogçöòéàÃÂÃÂ¥ÃÂ
çÃ¥îùãÃÂÃÂ
| |
− | | |
− | éÃÂÃÂæìáOWASPÃÂ¥ÃÂ
ìÃ¥øÃÂæÃÂðçÃÂÃÂTop 10ÃÂ¥ÃÂÃÂæÃÂàÃÂ¥ÃÂúçÃÂîÃÂ¥ÃÂÃÂçÃÂÃÂæÃÂûæÃÂÃÂçÃÂþæóÃÂïüÃÂäûÃ¥äûÃÂÃ¥ùôçÃÂúäþÃÂïüÃÂCross-Site Scripting(XSS)èêÿæÃÂôçÃÂú10Ã¥äçæÃÂûæÃÂÃÂäùÃÂéæÃÂïüÃÂçÃÂÃÂÃ¥ïæçÃÂÃÂÃÂ¥ÃÂÃÂæÃÂàÃÂ¥ÃÂúçÃÂîÃÂ¥ÃÂÃÂçöòè÷ïéÃÂãéÃÂÃÂèÃÂÃÂèéÃÂæìúçÃÂÃÂæÃÂûæÃÂÃÂæÿëçÃÂèXSSçÃÂÃÂæÃÂÃÂ
Ã¥ýâïüÃÂäúÃÂÃ¥ïæäøÃÂïüÃÂçþÃÂÃÂ¥ÃÂÃÂÃÂ¥ÃÂÃÂéÃÂòéÃÂèçÃÂÃÂBSIèèÃÂçÃÂë(Build-Security In,https://buildsecurityin.us-cert.gov/) ÃÂ¥ÃÂÃÂMitreçàÃÂçéöæéÃÂæçÃÂçÃÂÃÂCVEèóÃÂÃ¥îÃÂèÃÂÃÂÃ¥üñæÃÂçÃÂ¥ÃÂÃÂèáè(http://cve.mitre.org/) äúæéáïçäú1)Cross Site ScriptingèÃÂÃÂ2)SQL InjectionÃ¥÷òéÃÂãçúÃÂÃÂ¥ÃÂ
éÃ¥ùôÃÂ¥ÃÂÃÂçÃÂúÃÂ¥ÃÂ
èçÃÂÃÂéàÃÂèÃÂÃÂÃÂ¥ÃÂôéÃÂÃÂèóÃÂÃ¥îÃÂÃ¥üñéûÃÂ.
| |
− | | |
− | ===çÃÂôæÃÂÃ¥èÃÂÃÂçèÃÂÃ¥üÃÂçâüÃ¥îÃÂÃÂ¥ÃÂ
èÃÂ¥ÃÂÃÂèóêæÃÂÃÂéÃÂÃÂ===
| |
− | *[Ã¥ÿÃÂ
èæÃÂ*]A1. è÷èçöòçëÃÂÃÂ¥ÃÂ
Ã¥äþõÃÂ¥ÃÂÃÂäøò(Cross Site Scripting)
| |
− | *[Ã¥ÿÃÂ
èæÃÂ*]A2. æóèÃÂ¥ÃÂ
Ã¥çüúÃ¥äñ(Injection Flaw)
| |
− | *[Ã¥ûúèÃÂð*]A3. æÃÂáæÃÂÃÂæêÃÂæáÃÂÃÂ¥ÃÂ÷èáÃÂ(Malicious File Execution)
| |
− | *[Ã¥ûúèÃÂð*]A4. äøÃÂÃ¥îÃÂÃÂ¥ÃÂ
èçÃÂÃÂçÃÂéäûöÃÂ¥ÃÂÃÂèÃÂÃÂ(Insecure Direct Object Reference)
| |
− | *[éÃÂøæÃÂÃÂ*]A5. è÷èçöòçëÃÂèæÃÂæñÃÂÃÂ¥ÃÂýéÃÂà(Cross-Site Request Forgery)
| |
− | | |
− | | |
− | <nowiki>*</nowiki>OWASPÃÂ¥ÃÂðçÃÂãÃÂ¥ÃÂÃÂæÃÂÃÂÃ¥ü÷çÃÂÃÂÃ¥ûúèÃÂðÃÂ¥ÃÂÃÂÃÂ¥ÃÂîäýÃÂÃÂ¥ÃÂèéÃÂòèáÃÂæúÃÂçâüæêâæøìæÃÂÃÂïüÃÂÃ¥ðääûÃ¥æÃÂÿÃ¥úÃÂæéÃÂéÃÂÃÂ(æçÃÂ)ïüÃÂæÃÂÃÂéÃÂõÃ¥þêæÃÂÿÃ¥úÃÂèóÃÂéÃÂÃÂÃ¥îÃÂÃÂ¥ÃÂ
èäýÃÂæÃÂ¥ÃÂèæÃÂçïÃÂ(http://www.giscc.org.tw) äùÃÂãÃÂÃÂWebæÃÂÃÂçÃÂèçèÃÂÃ¥üÃÂÃ¥îÃÂÃÂ¥ÃÂ
èÃÂ¥ÃÂÃÂèÃÂÃÂæÃÂÃÂÃ¥üÃÂãÃÂÃÂïüÃÂäøæÃ¥ðÃÂ1èÃÂÃÂ2ÃÂ¥ÃÂÃÂçÃÂúÃ¥ÿÃÂ
èæÃÂæêâæøìéàÃÂ
çÃÂîïüÃÂ3èÃÂÃÂ4ÃÂ¥ÃÂÃÂçÃÂúÃ¥ûúèÃÂðæêâæøìéàÃÂ
çÃÂîïüÃÂèÃÂÃÂ5ÃÂ¥ÃÂÃÂçÃÂúéÃÂøæÃÂÃÂæêâæøìéàÃÂ
çÃÂîãÃÂÃÂ
| |
− | | |
− | ïüÃÂÃÂ¥ÃÂèÃ¥ïæÃÂ¥ÃÂÃÂæáÃÂäþÃÂäøÃÂïüÃÂæêâæøìäøæäÿîæÃÂã1èÃÂÃÂ2ÃÂ¥ÃÂóÃÂ¥ÃÂïéÃÂÿÃÂ¥ÃÂ
ÃÂçõÃÂÃ¥äçÃ¥äÃÂæÃÂøçÃÂÃÂWebèóÃÂÃ¥îÃÂÃ¥èÃÂèÃÂÃÂ
ãÃÂÃÂ
| |
− | | |
− | ===ÃÂ¥ÃÂàäøÃÂèÿðæüÃÂæôÃÂéÃÂÃÂæÃÂÃ¥éÃÂàæÃÂÃÂæÃÂÃÂèÃÂÃÂWebäüúæÃÂÃÂÃÂ¥ÃÂèÃÂ¥ÃÂÃÂÃ¥äÃÂéÃÂèèèÃÂÃ¥îÃÂæÃÂÃÂéÃÂÃÂ===
| |
− | *Information Leakage and Improper Error Handling
| |
− | *Broken Authentication and Session Management
| |
− | *Insecure Cryptographic Storage
| |
− | *Insecure Communications
| |
− | *Failure to Restrict URL Access
| |
− | | |
− | == æÃÂÃÂÃÂ¥ÃÂáÃÂ¥ÃÂÃÂèáè (Member List) ==
| |
− | Coming up soon!
| |
− | | |
− | [http://www.owasp.org.tw http://www.owasp.org.tw/dot.png]
| |
Welcome to the Taiwan chapter homepage. The chapter leader position is OPEN.
Everyone is welcome to join us at our chapter meetings.