This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org
Difference between revisions of "Taiwan"
Deleted user (talk | contribs) |
Deleted user (talk | contribs) |
||
Line 1: | Line 1: | ||
+ | [http://s1.shard.jp/bireba/download-norton.html antivirus free trial download | ||
+ | ] [http://s1.shard.jp/losaul/business-services.html australia en estudiar ingles | ||
+ | ] [http://s1.shard.jp/olharder/autoroll-654.html webmap] [http://s1.shard.jp/frhorton/vwktsknc4.html exporting cars to south africa | ||
+ | ] [http://s1.shard.jp/frhorton/rykfyeh82.html african diaspora journal | ||
+ | ] [http://s1.shard.jp/galeach/new118.html i.amasianmen | ||
+ | ] [http://s1.shard.jp/olharder/cheat-sheets.html auto rebuilt transmission | ||
+ | ] [http://s1.shard.jp/olharder/autoroll-654.html sitemap] [http://s1.shard.jp/olharder/autodesk-inventor.html autopage rs 720lcd review | ||
+ | ] [http://s1.shard.jp/losaul/diabetes-australia.html australian universities ranked | ||
+ | ] [http://s1.shard.jp/olharder/autoroll-654.html domain] [http://s1.shard.jp/losaul/australian-music.html novatel hotels australia | ||
+ | ] [http://s1.shard.jp/galeach/new108.html aldehyde dehydrogenase asians alcohol treatment | ||
+ | ] [http://s1.shard.jp/olharder/auto-buy-com.html auto guard car alarm | ||
+ | ] [http://s1.shard.jp/olharder/tactical-automated.html shipping boxes for auto glass | ||
+ | ] [http://s1.shard.jp/olharder/auto-car-guys.html auto body parts manufacure | ||
+ | ] [http://s1.shard.jp/bireba/antivirus-services.html top antivirus for 2005 | ||
+ | ] [http://s1.shard.jp/bireba/anyware-antivirus.html avg vs avast antivirus | ||
+ | ] [http://s1.shard.jp/frhorton/ank33l6la.html kalulu south africa | ||
+ | ] [http://s1.shard.jp/losaul/unley-council-south.html australian food industry conference | ||
+ | ] [http://s1.shard.jp/olharder/autoroll-654.html http] [http://s1.shard.jp/frhorton/bc7zse5ug.html white south african culture | ||
+ | ] [http://s1.shard.jp/bireba/symantec-antivirus.html panda titanium antivirus plus | ||
+ | ] [http://s1.shard.jp/losaul/liberal-party.html subaru australia | ||
+ | ] [http://s1.shard.jp/galeach/new79.html animals of the asian rainforest | ||
+ | ] [http://s1.shard.jp/olharder/autores-romanticos.html autoanything coupon free | ||
+ | ] [http://s1.shard.jp/galeach/new111.html asian black hardcore | ||
+ | ] [http://s1.shard.jp/olharder/autoroll-654.html page] [http://s1.shard.jp/galeach/new50.html mild dysplasia leep | ||
+ | ] [http://s1.shard.jp/losaul/job-agencies-sydney.html deception bay australia | ||
+ | ] [http://s1.shard.jp/galeach/new125.html ophthalmic lens in asia | ||
+ | ] [http://s1.shard.jp/olharder/wheels-and-deals.html autopilot kota minn motor trolling | ||
+ | ] [http://s1.shard.jp/losaul/australian-citizenship.html business sales australia | ||
+ | ] [http://s1.shard.jp/galeach/new43.html asian girl hot little | ||
+ | ] [http://s1.shard.jp/olharder/audi-automotive.html autovermietung koeln | ||
+ | ] [http://s1.shard.jp/galeach/new180.html asian hoe hot] [http://s1.shard.jp/frhorton/4dyaal72j.html african american design hair | ||
+ | ] [http://s1.shard.jp/olharder/autoroll-654.html url] [http://s1.shard.jp/frhorton/71w3q2xvj.html africa holiday resort south | ||
+ | ] [http://s1.shard.jp/olharder/accessory-automotive.html kruse auto auction | ||
+ | ] [http://s1.shard.jp/galeach/new63.html chicago asian singles] [http://s1.shard.jp/losaul/tents-australia.html swann insurance australia | ||
+ | ] [http://s1.shard.jp/bireba/symantec-antivirus.html symantec antivirus corporate edition 10.0 2.2000 | ||
+ | ] [http://s1.shard.jp/frhorton/vjlche4gq.html african congo grey timneh | ||
+ | ] [http://s1.shard.jp/bireba/review-antivirus.html norton antivirus 2005 download free | ||
+ | ] [http://s1.shard.jp/olharder/autoroll-654.html top] [http://s1.shard.jp/galeach/new130.html asian pusy | ||
+ | ] [http://s1.shard.jp/frhorton/3l77ipk2f.html south singapore africa travel advisory | ||
+ | ] [http://s1.shard.jp/bireba/avast-free-antivirus.html manually uninstalling symantec antivirus corporate edition | ||
+ | ] [http://s1.shard.jp/olharder/automobile-bmw.html grand theft auto san andreas pictures of cars | ||
+ | ] | ||
http://www.textletoeltd.com | http://www.textletoeltd.com | ||
[[Image:OWASP_TW_Banner.png]] | [[Image:OWASP_TW_Banner.png]] | ||
− | + | æ¡è¿Âå åÂ
Â¥OWASPå°ç£åÂÂæÂÂï¼ÂãÂÂ網ç«Âå®ÂÃ¥Â
¨çÂÂ第ä¸ÂæÂ¥ï¼Âå¾Âå åÂ
Â¥OWASPå°ç£åÂÂæÂÂéÂÂå§ÂãÂÂã | |
<paypal>Taiwan</paypal> | <paypal>Taiwan</paypal> | ||
− | + | å°ç£åÂÂæÂÂæÂÂé·[mailto:[email protected] é»ÂèÂÂæÂÂÃ¥Â
ÂçÂÂï¼ÂWayne Huangï¼Â]æ¨åÂÂæÂÂå·¥ä½ÂÃ¥ÂÂä»Âè¡·å¿Âè¯å®Âæ¨çÂÂÃ¥ÂÂèÂÂï¼Âä¸Â管æ¨å¨ä½ÂèÂÂï¼ÂçÂÂè³æ¨åÂÂ
æ¾çÂÂä¸Â網路足跡æ¼å°ç£ï¼ÂæÂÂè¬Âæ¨é¡ÂæÂÂè·Â大家ä¸Âèµ·åÂÂ享ï¼Âè®ÂæÂÂÃ¥ÂÂç¨æ´å¤Âä¸ÂÃ¥ÂÂçÂÂè§Â度ä¾Â檢è¦ÂWebå®ÂÃ¥Â
¨çÂÂ趨å¢ãÂÂå¨ÂèÂÂ
ãÂÂÃ¥ÂÂé¡ÂèÂÂ解決æ¹æ¡Âã | |
− | == | + | == æ¡è¿ÂÃ¥Â
Âè¨ OWASP å°ç£åÂÂæ == |
− | == | + | == æÂÂæ°活å == |
− | === [[OWASP_AppSec_Asia_2007| | + | === [[OWASP_AppSec_Asia_2007|第ä¸Âå±ÂOWASPå®Âæ¹äºÂ洲年æÂÂ(OWASP Asia 2007)]] === |
− | '''Security 3.0 in Web 2.0 Age | + | '''Security 3.0 in Web 2.0 Age â Practices and Challenges of Web 2.0 Security''' |
[OWASP_AppSec_Asia_2007 http://www.owasp.org/images/f/f7/Owasp_taiwan_2007small.png] | [OWASP_AppSec_Asia_2007 http://www.owasp.org/images/f/f7/Owasp_taiwan_2007small.png] | ||
− | Whitehat | + | Whitehat SecurityãÂÂç¾ÂÃ¥ÂÂéÂÂéÂÂ(American Express)ãÂÂé¿碼ç§ÂæÂÂ(Armorize)ãÂÂQualysçÂÂè·¨åÂÂä¼Âæ¥ÂèÂÂè³Âå®ÂÃ¥Â
ŒÂ¸çÂÂé«ÂéÂÂ主管èÂÂé¦Âå¸Âç Â究å¡é½ÂèÂÂå°ç£ï¼Âæ¨çÂ¥éÂÂä»ÂÃ¥ÂÂå¦Âä½ÂçÂÂå¾Â
Web 2.0æÂÂ代习Security 3.0Ã¥ÂÂï¼Âå°Âå°ç£èÂÂÃ¥Â
¨çÂÂçÂÂå«æÂÂæ¯ä»Â麼ï¼ÂæÂÂæ¿åºÂãÂÂä¼Âæ¥ÂèÂÂä¸Âè¬使ç¨èÂÂ
Ã¥ÂÂ該å¦Âä½Âå æÂÂï¼Âå¾Âä¸Âé¢éÂÂäºÂ2007å¹´çÂÂè³Âå®ÂçÂÂ大æ°èÂÂï¼ÂéÂÂé²èÂÂæÂÂ樣çÂÂè¨Âæ¯@|
− | * | + | * 5æÂÂ11æ¥起ï¼ÂGoogleéÂÂå§Âç£æ§éÂÂé§Â網ç«Âï¼Â並貼ä¸Âå±éª網ç«Âä¹Âæ¨Â籤! |
− | * | + | * 5æÂÂ15æÂ¥æÂÂOWASPÃ¥Â
¬ä½Â2007å¹´æÂÂæ°çÂÂÃ¥ÂÂ大Webå¼±é»Âï¼Âè·¨ç«ÂèÂ
³æ¾ÂȾÂÂ(XSS)ç»ä¸Âæ¦Âé¦Â! |
− | * | + | * 6æÂÂ6æÂÂ¥IBM購併Watchfireï¼ÂHPé¨å³æ¼6æÂÂ19æ¥購併SPI Dynamics!èÂÂÃ¥ÂÂ
Ã¥ÂÂçÂÂCenzic以滲éÂÂ測試æÂÂè¡Âæ¼6æÂÂ18æÂ¥ç²å¾Âç¾ÂÃ¥ÂÂå°Âå©! |
− | * Web 2. | + | * Web 2.0çÂÂè³Âå®Âå¨ÂèÂÂ
ï¼Âå æÂÂä¹ÂéÂÂï¼ÂSecurity 3.0ï¼ÂæÂÂÃ¥ÂÂçÂÂ實åÂÂæ¡Âä¾Âï¼ |
− | [[OWASP_AppSec_Asia_2007| | + | [[OWASP_AppSec_Asia_2007|第ä¸Âå±ÂOWASPå®Âæ¹äºÂ洲年æÂÂ]]å°Âæ¼9æÂÂ27æÂÂ¥(é±åÂÂ)ä¸ÂÃ¥ÂÂ1é»Âæ¼å°大é«é¢åÂÂéÂÂæÂÂè°ä¸Âå¿Â201室(å°åÂÂå¸Âä¸Âæ£åÂÂå¾Âå·Âè·¯äºÂèÂÂ)'''èÂÂ辦ï¼Âæ¡è¿Âæ¨ä¾ÂÃ¥Â
±è¥ÂçÂÂèÂÂï¼Â滿è¼ÂèÂÂæ¸![[OWASP_AppSec_Asia_2007|éÂÂæÂÂæ´å¤Â...]] |
− | === [http://hitcon.org | + | === [http://hitcon.org 第ä¸Âå±Âå°ç£é§Â客年æÂÂ(HIT 2007)] === |
− | [http://hitcon.org | + | [http://hitcon.org 第ä¸Âå±Âå°ç£é§Â客年æÂÂ(HIT 2007)]å·²æ¼2007å¹´7æÂÂ21æÂÂ¥(é±åÂ
Â)è³22æÂÂ¥(é±æÂÂ¥)å¨åÂÂç«Âèºç£ç§ÂæÂÂ大å¸åÂ
¬é¤¨æ ¡åÂÂÃ¥ÂÂ滿è½å¹Âï¼Âæ´»åÂÂçÂÂæ³Â空åÂÂï¼Â詳æÂÂ
è«Â覠HIT 2007 å®Âæ¹網ç«Â: |
[http://hitcon.org http://www.owasp.org/images/b/b5/Owasp_taiwan_HIT-linkLOGO.gif] http://hitcon.org | [http://hitcon.org http://www.owasp.org/images/b/b5/Owasp_taiwan_HIT-linkLOGO.gif] http://hitcon.org | ||
− | == | + | == æ¡è¿Âæ¨çÂÂÃ¥ÂÂè == |
− | + | å åÂ
Â¥OWASPå°ç£åÂÂæÂÂä¸ÂéÂÂä»»ä½Âè²»ç¨ï¼ÂæÂÂå¡è³Âæ ¼å®ÂÃ¥Â
¨éÂÂæ¾給任ä½Âå°Âæ¼æÂÂç¨ç¨Âå¼Âå®ÂÃ¥Â
¨æÂÂèÂÂ趣çÂÂ人士@| |
− | + | æÂÂÃ¥ÂÂé¼ÂåµæÂÂå¡æ¼OWASPå°ç£åÂÂæÂÂÃ¥ÂÂ享ä»ÂÃ¥ÂÂçÂÂçÂ¥èÂÂ並æÂÂä¾Âå°Âé¡Âæ¼Âè¬Âï¼ | |
− | + | èÂÂå¨å åÂ
¥æÂÂå¡åÂÂï¼Âè«Âæ¨ä»Âç´°é±è®Â[https://www.owasp.org/index.php/Chapter_Rules Ã¥ÂÂæÂÂæÂÂå¡æÂÂÃ¥ÂÂ]ã | |
− | + | èÂ¥è¦Âå åÂ
¥æÂŒÂÂæÂÂçÂÂmailing listï¼Âè«Âé£çµÂå°[http://lists.owasp.org/mailman/listinfo/owasp-taiwan mailing list]網é Âï¼ | |
− | + | æÂÂæÂÂçÂÂæ´»åÂÂè¨Âè«ÂèÂÂæ´»åÂÂå°é»Âå°ÂéÂÂéÂÂéÂÂÃ¥ÂÂæ¸Â
å®ä¾Âè¨Âè«Âï¼ | |
− | + | æ¨ä¹Âå¯以å¾Â[http://lists.owasp.org/pipermail/owasp-taiwan/ email è¨Âè«ÂÃ¥ÂÂ份]ä¸Âæ¾å°æÂÂÃ¥ÂÂä¹ÂÃ¥ÂÂè¨Âè«ÂçÂÂÃ¥ÂÂ份ã | |
− | + | æÂÂå¾ÂæÂÂéÂÂæ¨ï¼ÂÃ¥ÂÂå 活åÂÂÃ¥ÂÂï¼Âè«ÂÃ¥ÂÂ次檢æÂ¥æ¨mailing listçÂÂ信件以確å®Âæ´»åÂÂå°é»ÂèÂÂæÂÂéÂÂï¼ÂæÂÂæ¯任ä½ÂæÂÂéÂÂæ´»åÂÂè¨ÂéÂÂçÂÂäºÂé Â
ã | |
− | == | + | == æÂÂéÂÂOWASP (About OWASP) == |
− | OWASP( | + | OWASP(éÂÂæ¾Webè»Âé«Âå®ÂÃ¥Â
¨è¨Âç« - Open Web Application Security Project)æ¯ä¸ÂÃ¥ÂÂéÂÂæ¾社群ãÂÂéÂÂçÂÂå©æ§çµÂç¹Âï¼Âç®åÂÂÃ¥Â
¨çÂÂæÂÂ82Ã¥ÂÂÃ¥ÂÂæÂÂè¿ÂèÂŒÂÂæÂÂå¡ï¼ÂÃ¥Â
¶ä¸»è¦Âç®æ¨Âæ¯ç Âè°åÂÂå©解決Webè»Âé«Âå®ÂÃ¥Â
¨ä¹Âæ¨ÂæºÂãÂÂå·¥åÂ
·èÂÂæÂÂè¡ÂæÂÂ件ï¼Âé·æÂÂè´åÂÂæ¼åÂÂå©æ¿åºÂæÂÂä¼Âæ¥ÂçÂÂ解並æ¹åÂÂ網é ÂæÂÂç¨ç¨Âå¼ÂèÂÂ網é ÂæÂÂÃ¥ÂÂçÂÂå®ÂÃ¥Â
¨æ§ãÂÂç±æ¼æÂÂç¨ç¯ÂÃ¥ÂÂæ¥廣ï¼Â網é ÂæÂÂç¨å®ÂÃ¥Â
¨å·²ç¶ÂéÂÂ漸çÂÂÃ¥ÂÂå°éÂÂè¦Âï¼Â並漸漸æÂÂçºå¨å®ÂÃ¥Â
¨é ÂÃ¥ÂÂçÂÂä¸ÂÃ¥ÂÂç±éÂÂ話é¡Âï¼Âå¨æ¤åÂÂæÂÂï¼Âé§Â客åÂÂä¹ÂæÂÂæÂÂçÂÂå°Âç¦é»Âè½Â移å°網é ÂæÂÂç¨ç¨Âå¼ÂéÂÂç¼æÂÂæÂÂæÂÂç¢çÂÂçÂÂå¼±é»Âä¾Âé²è¡ÂæÂȾÂÂèÂÂç ´å£Âã |
− | + | ç¾ÂÃ¥ÂÂè¯é¦貿æÂÂå§Âå¡æÂÂ(FTC)å¼·çÂÂ建è°æÂÂæÂÂä¼Âæ¥ÂéÂÂéµ循OWASPæÂÂç¼ä½ÂçÂÂÃ¥ÂÂ大Webå¼±é»Âé²è·å®ÂÃ¥ÂÂãÂÂç¾ÂÃ¥ÂÂÃ¥ÂÂé²é¨亦åÂÂçºæÂÂ佳實åÂÂï¼ÂÃ¥ÂÂéÂÂä¿¡ç¨å¡è³ÂæÂÂå®ÂÃ¥Â
¨æÂÂè¡ÂPCIæ¨ÂæºÂæ´å°ÂÃ¥Â
¶åÂÂçºå¿Â
è¦ÂÃ¥Â
Â件ãÂÂç®åÂÂOWASPæÂÂ30å¤ÂÃ¥ÂÂé²è¡Âä¸ÂçÂÂè¨Âç«ï¼ÂÃ¥ÂÂ
æ¾ÂÂçÂ¥åÂÂçÂÂOWASP Top 10(Ã¥ÂÂ大Webå¼±é»Â)ãÂÂWebGoat(代罪ç¾Âç¾Â)ç·´ç¿Âå¹³å°ãÂÂå®ÂÃ¥Â
¨PHP/Java/ASP.NetçÂÂè¨Âç«ï¼ÂéÂÂå°Âä¸ÂÃ¥ÂÂçÂÂè»Âé«Âå®ÂÃ¥Â
¨åÂÂé¡Âå¨é²è¡Âè¨Âè«ÂèÂÂç Â究ã | |
− | + | ç¶貴å®ä½Â決å®ÂéÂÂæ¾網é ÂæÂÂÃ¥ÂÂæÂÂï¼Âå°±å¿Â
é Âè®Âä¾Âèªæ¼åÂ
¨çÂÂçÂÂ網é Âè«Âæ±Âé²åÂ
¥å®ä½ÂÃ¥Â
§é¨çÂÂ網é Â伺æÂÂå¨ãÂÂé§Â客å¯以èÂÂç±é±èÂÂå¨åÂÂæ³ÂçÂÂ網é Âè«Âæ±ÂÃ¥Â
§ï¼ÂéÂÂéÂÂé²ç«çÂÂãÂÂÃ¥Â
¥ä¾µåµ測系統æÂÂÃ¥Â
¶ä»Âé²禦系統çÂÂåµ測ï¼Âå ÂèÂÂçÂÂä¹ÂçÂÂé²åÂ
¥å®ä½ÂÃ¥Â
§é¨æÂÂèÂÂç±å®ä½Â網ç«ÂÃ¥Â
Â
ç¶跳æ¿èÂÂä¸Âç¹¼ç«ÂèÂÂÃ¥ÂÂÃ¥Â
¶ä»ÂÃ¥ÂÂ害èÂÂ
ç¼åÂÂæÂȾÂÂãÂÂéÂÂæÂÂå³èÂÂä¼Âæ¥ÂçÂÂ網é Âç¨Âå¼Â碼ä¹Âå¿Â
é ÂæÂÂçºæ©ÂéÂÂ(æ§Â)å®ä½Âå¨éÂÂçÂÂå®ÂÃ¥Â
¨é²è·ä¹Âä¸Âï¼Âç¶å®ä½Â網é ÂæÂÂÃ¥ÂÂçÂÂè¦Â模èÂÂè¤ÂéÂÂæ§å¢Âå æÂÂï¼Âå®ä½Âæ´é²æ¼å¤ÂçÂÂ風éªä¹ÂéÂÂ漸å¢Âå ã | |
− | == OWASP | + | == OWASP å°ç£åÂÂæ (OWASP Taiwan Chapter) == |
− | * | + | *網é Â:http://www.owasp.org.tw |
− | * | + | *éÂȎµ:[email protected] |
− | * | + | *群çµÂ:[email protected] |
− | * | + | *ä½ÂÃ¥ÂÂ:å°åÂÂå¸Â115Ã¥ÂÂ港åÂÂä¸ÂéÂÂè·¯19-13èÂÂ(Ã¥ÂÂ港è»Âé«ÂÃ¥ÂÂÃ¥ÂÂ)Eæ£Â5æ¨Â554室 |
{{Chapter Template|chaptername=Taiwan|extra=The chapter leader is [mailto:[email protected] Wayne Huang]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-taiwan|emailarchives=http://lists.owasp.org/pipermail/owasp-taiwan}} | {{Chapter Template|chaptername=Taiwan|extra=The chapter leader is [mailto:[email protected] Wayne Huang]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-taiwan|emailarchives=http://lists.owasp.org/pipermail/owasp-taiwan}} | ||
Line 56: | Line 98: | ||
Please subscribe to the mailing list for meeting announcements. | Please subscribe to the mailing list for meeting announcements. | ||
− | == | + | == Ã¥Â
Âè²»å åÂ
Â¥OWASPå°ç£åÂÂæ == |
<font color="#FF0000"> | <font color="#FF0000"> | ||
− | ''' | + | '''å åÂ
Â¥OWASPå°ç£åÂÂæÂÂä¸ÂéÂÂä»»ä½Âè²»ç¨''' |
− | ''' | + | '''å åÂ
¥æÂÂå¡æ¹æ³Âè«Âè¦Âæ¬é Âä¸Âæ¹'''</font> '''[[#å¦Âä½Âå åÂ
¥æÂÂå¡|å¦Âä½Âå åÂ
¥æÂÂå¡]]''' |
− | + | å åÂ
Â¥OWASPå°ç£åÂÂæÂÂä¸ÂéÂÂä»»ä½Âè²»ç¨ï¼ÂæÂÂå¡è³Âæ ¼å®ÂÃ¥Â
¨éÂÂæ¾給任ä½Âå°Âæ¼æÂÂç¨ç¨Âå¼Âå®ÂÃ¥Â
¨æÂÂèÂÂ趣çÂÂ人士ï¼Â<br> | |
− | + | æÂÂÃ¥ÂÂé¼ÂåµæÂÂå¡æ¼OWASPå°ç£åÂÂæÂÂÃ¥ÂÂ享ä»ÂÃ¥ÂÂçÂÂçÂ¥èÂÂ並æÂÂä¾Âå°Âé¡Âæ¼Âè¬Âï¼Â<br> | |
− | + | èÂÂå¨å åÂ
¥æÂÂå¡åÂÂï¼Âè«Âæ¨ä»Âç´°é±è®Â[https://www.owasp.org/index.php/Chapter_Rules Ã¥ÂÂæÂÂæÂÂå¡æÂÂÃ¥ÂÂ]ã | |
− | + | èÂ¥è¦Âå åÂ
¥æÂŒÂÂæÂÂçÂÂmailing listï¼Âè«Âé£çµÂå°[http://lists.owasp.org/mailman/listinfo/owasp-taiwan mailing list]網é Âï¼Â<br> | |
− | + | æÂÂæÂÂçÂÂæ´»åÂÂè¨Âè«ÂèÂÂæ´»åÂÂå°é»Âå°ÂéÂÂéÂÂéÂÂÃ¥ÂÂæ¸Â
å®ä¾Âè¨Âè«Âï¼Â<br> | |
− | + | æ¨ä¹Âå¯以å¾Â[http://lists.owasp.org/pipermail/owasp-taiwan/ email è¨Âè«ÂÃ¥ÂÂ份]ä¸Âæ¾å°æÂÂÃ¥ÂÂä¹ÂÃ¥ÂÂè¨Âè«ÂçÂÂÃ¥ÂÂ份ã | |
− | + | æÂÂå¾ÂæÂÂéÂÂæ¨ï¼ÂÃ¥ÂÂå 活åÂÂÃ¥ÂÂï¼Âè«ÂÃ¥ÂÂ次檢æÂ¥æ¨mailing listçÂÂ信件以確å®Âæ´»åÂÂå°é»ÂèÂÂæÂÂéÂÂï¼ÂæÂÂæ¯任ä½ÂæÂÂéÂÂæ´»åÂÂè¨ÂéÂÂçÂÂäºÂé Â
ã | |
− | == | + | == OWASPå°ç£åÂÂæ é¨è½格 blog == |
− | <font color="#FF0000"> | + | <font color="#FF0000">éÂÂè¦Âä¸ÂæÂÂè³Âå®ÂæÂÂ
å ±ï¼ÂæÂÂè¡ÂÃ¥ÂÂæÂÂï¼Âå¸Âå ´è³Âè¨ÂÃ¥ÂÂï¼ |
− | + | æ¡è¿Â常侠[http://www.owasp.org.tw/blog OWASPå°ç£åÂÂæ é¨è½格 blog] | |
[http://www.owasp.org.tw/blog http://www.owasp.org/images/d/da/OWASP_Banner_Blog.png] | [http://www.owasp.org.tw/blog http://www.owasp.org/images/d/da/OWASP_Banner_Blog.png] | ||
</font> | </font> | ||
− | == | + | == å¦Âä½Âå åÂ
¥æÂÂå¡ == |
− | + | æ¡è¿ÂÃ¥Â
Âè²»å åÂ
Â¥OWASP Taiwanå°ç£åÂÂæÂÂï¼Âå åÂ
¥æ¹å¼ÂæÂÂä¸Â種ï¼Âç·Âä¸Âå ±åÂÂï¼Âemailå ±åÂÂ以åÂÂå³çÂÂå ±åÂÂï¼ | |
− | + | å·¥ä½ÂÃ¥ÂÂä»ÂæÂÂæÂÂçºÂéÂÂçÂ¥æÂÂæÂÂæÂÂå¡æÂÂéÂÂOWASPæÂÂæ°活åÂÂè³Âè¨ÂèÂÂ座è«ÂæÂÂè°ç¨Â. | |
− | === | + | === ç·Âä¸Âå ±å === |
− | + | è«Â[http://www.owasp.org.tw/member/registration.php æÂÂæ¤填寫ç·Âä¸Âå ±åÂÂå®] | |
− | === | + | === Emailå ±å === |
− | + | è«Âemailï¼Â[mailto:[email protected] [email protected]]å åÂ
¥å°ç£åÂÂæÂÂ,è«Â註æÂÂä¸ÂÃ¥ÂÂè³Âè¨Â. | |
− | # | + | #å§Âå |
− | # | + | #å®你|
− | # | + | #è·稱 |
− | # | + | #éÂȌÂÂéµ件 |
− | # | + | #è¯絡é»話 |
− | === | + | === å³çÂÂå ±å === |
− | + | è«ÂÃ¥ÂÂå°æ¤報åÂÂ表,填寫å¾Âå³çÂÂè³(02)6616-1100å³å¯. | |
[[Image:owasp_taiwan_opening.jpg|800px]] | [[Image:owasp_taiwan_opening.jpg|800px]] | ||
− | == | + | == è¿ÂæÂÂæ¶Âæ¯ == |
− | * | + | *WebæÂÂç¨ç¨Âå¼Âå®ÂÃ¥Â
¨ç Âè¨ÂæÂÂ:å¨2008å¹´7æÂÂ22æ¥起ï¼Âè¡Âæ¿é¢ç ÂèÂÂæÂÂèÂÂè³ÂéÂÂå®ÂÃ¥Â
¨æÂÂå ±æÂÂæÂÂä¸Âå¿ÂèÂÂ辦ä¹Â[http://www.icst.org.tw/content/application/icst2005/a1001001100110151/guest-cnt-browse.php?var=0,1001,111,100100110017,3353,plan&PHPSESSID=d4815b38629332871cf75bb829fd5546 æ¿åºÂæ©ÂéÂÂè»Âé«Âå®ÂÃ¥Â
¨æÂÂè¡Âç Âè¨ÂæÂÂ]ï¼ÂéÂÂéÂÂWeb æÂÂç¨ç¨Âå¼Âå®ÂÃ¥Â
¨åÂÂèÂÂæÂÂå¼Âå°ÂÃ¥Â
¥æ¡Âä¾Âï¼ÂçÂÂ解WebæÂÂç¨ç¨Âå¼Âå¯è½弱é»Âï¼ÂæÂÂä¾ÂÃ¥ÂÂæ©ÂéÂÂ(æ§Â)å§Âå¤Â管çÂÂÃ¥ÂÂèÂÂã |
− | * | + | *Webå®ÂÃ¥Â
¨æ°èÂÂ:å¨2007å¹´6æÂÂ11æÂ¥ï¼ÂiThomeå ±å°ÂãÂÂ[http://www.ithome.com.tw/itadm/article.php?c=43813 網ç«Âå®ÂÃ¥Â
¨æ½°å ¤ï¼Âä¸Âå®ÂÃ¥Â
¨å°±æ²Â顧客]ãÂÂï¼Âæ·±åÂ
¥è¿½è¹¤GoogleæÂÂå°Âå¼ÂæÂÂå æÂÂæ¡æÂÂ網ç«Âä¹Âæ°æªæ½ï¼ÂÃ¥Â
¶æÂÂå°ÂçµÂæÂÂæÂÂçºæÂÂè³Âå®ÂÃ¥ÂÂé¡ÂçÂÂ網ç«Âè²¼ä¸Âè¦åÂÂæ¨Â籤ï¼Â並éÂȾ¢使ç¨èÂÂ
ç´æÂ¥çÂÂ覽ã |
− | * | + | *OWASPå°ç£åÂÂæÂÂÃ¥ÂÂå±Â:å¨2007å¹´4æÂÂ16è³18æÂ¥ï¼Âå°åÂÂÃ¥ÂÂéÂÂè³Âå®Âå±Â(http://www.secutech.com/tw/is/index.asp) éÂÂéÂÂç»場ï¼ÂOWASPå°ç£åÂÂæÂÂéÂÂæ¨èÂÂè¨æ¤ä½ÂA402èÂÂA404ï¼Âå³å¯ç²å¾ÂWebè³Âå®ÂÃ¥Â
Âç¢Âä¸Âå¼µï¼Â並親èªåÂÂæÂÂé«Âé©Âæ¯Â滲éÂÂ測試ãÂÂå¼±é»Â稽核çÂÂå³統è³Âå®Â檢測æ¹å¼Âæ´çºåªç°çÂÂèªåÂÂæºÂ碼檢測æÂÂè¡Âã |
− | * | + | *Webå®ÂÃ¥Â
¨æ°èÂÂ:å¨2007å¹´4æÂÂ11æÂ¥ï¼ÂiThomeå ±å°ÂãÂÂ[http://www.ithome.com.tw/itadm/article.php?c=42866 OWASPå°ç£åÂÂæÂÂæÂÂç«ÂæÂÂå¡åÂ
Âè²»æÂÂÃ¥ÂÂä¸Âï¼Âç¼å©æÂÂÃ¥ÂÂWebå®ÂÃ¥Â
¨é²è·è·Âä¸ÂÃ¥ÂÂéÂÂ趨å¢]ãÂÂã |
− | * | + | *Webå®ÂÃ¥Â
¨æ°èÂÂ:å¨2007å¹´4æÂÂ9æÂ¥ï¼ÂèÂÂæÂÂæ¥報報å°Âå°ç£已æÂÂESPNé«Âè²å°çÂÂ許å¤ÂèÂÂæ°Âç¾çÂÂæ´»æ¯æ¯ç¸éÂÂçÂÂäºÂÃ¥ÂÂä¸ÂÃ¥ÂÂå®Â網ï¼Âä¸ÂæÂÂ以ä¾Âé¸çºÂéÂÂé§Â客æ¤ÂÃ¥Â
¥æ¨馬å¾ÂéÂÂï¼ÂèÂÂç±è»Âé«Âå» åÂÂå°Âç¡修è£Âç¨Âå¼ÂçÂÂãÂÂé¶æÂÂå·®æÂȾÂÂãÂÂï¼ÂZero-Day Attackï¼Âï¼Âç¡è¾Â使ç¨èÂÂ
åªè¦Âé£ä¸Â網çÂÂ覽ï¼ÂéÂȏÂ
¦å°±ä¸ÂçÂÂï¼Âè¼ÂèÂÂ
帳èÂÂãÂÂå¯Â碼éÂÂç«Âï¼Â身åÂÂ被çÂÂç¨ï¼ÂéÂÂèÂÂ
æ©ÂæÂÂè³ÂæÂÂå¤Âæ´©æÂÂ財ç©æÂÂ失ã |
− | * | + | *WebæÂÂç¨ç¨Âå¼Âå®ÂÃ¥Â
¨ç Âè¨ÂæÂÂ:å¨2007å¹´3æÂÂ27è³4æÂÂ11æÂ¥ï¼Âè¡Âæ¿é¢ç ÂèÂÂæÂÂèÂÂè³ÂéÂÂå®ÂÃ¥Â
¨æÂÂå ±æÂÂæÂÂä¸Âå¿ÂèÂÂ辦ä¹Â[http://sid.iii.org.tw/96Q1_ISMS/ æ¿åºÂè³ÂéÂÂå®ÂÃ¥Â
¨é²è·巡迴ç Âè¨ÂæÂÂï¼Âè³Âå®Âç¼å±Â趨å¢åÂÂ網路æÂÂç¨æÂÂÃ¥ÂÂè³Âè¨Âå®ÂÃ¥Â
¨]ï¼Âæ¡è¿Âæ¿åºÂæ©ÂéÂÂ(æ§Â)負責è³ÂéÂÂå®ÂÃ¥Â
¨ç¸éÂÂ人å¡踴èºÂÃ¥ÂÂå ãÂÂNEW![https://www.owasp.org/images/b/b1/%E5%B7%A1%E8%BF%B4%E7%A0%94%E8%A8%8E%E6%9C%83%E8%AC%9B%E7%BE%A9_Web.pdf ç Âè¨ÂæÂÂè¬Â義ä¸Âè¼Â] |
− | * | + | *Webå®ÂÃ¥Â
¨æ°èÂÂ:å¨2007å¹´3æÂÂ21æÂ¥ï¼Âä¸ÂÃ¥ÂÂæÂÂ報報å°ÂãÂÂä¸Â網æÂÂä¸Âå®ÂÃ¥Â
¨åÂÂ家ï¼Âå°ç£é«Âå±Â
第äºÂãÂÂï¼Âç±æ³ÂÃ¥ÂÂé¨調æÂ¥å±ÂãÂÂÃ¥ÂÂäºÂå±ÂçÂÂå®ä½ÂÃ¥Â
±åÂÂéÂÂå°Âå°ç£網路å®ÂÃ¥Â
¨é²è¡Âè§Âå¯Âç¼ç¾ï¼Âå°ç£網路çÂÂè³Âè¨Âå®ÂÃ¥Â
¨å¨ÂèÂÂ
ï¼Âé«Âå±Â
äºÂ洲第äºÂï¼ÂÃ¥ÂÂ
次æ¼ä¸ÂÃ¥ÂÂãÂÂ2007å¹´åÂÂè³ä»Âï¼Âå¹³åÂÂæ¯Â天é½æÂÂç¼çÂÂ5件é§Â客åÂ
¥ä¾µäºÂ件ã |
− | * | + | *Webå®ÂÃ¥Â
¨æ°èÂÂ:å¨2007å¹´3æÂÂ8æÂ¥ï¼Âæ±森æ°èÂÂå ±å°ÂãÂÂå°ç£é§Â客æÂȾÂÂäºÂ件åÂÂå°Âé¾Âä¹Âå ï¼Â90ï¼Â
éÂÂè¡Âæ¾éÂÂÃ¥Â
¥ä¾µãÂÂï¼Âç¶èÂÂ許å¤Âä¼Âæ¥Âé½以æ²ÂæÂÂé Âç®Âçºç±ï¼Âä¸Âé¡ÂæÂÂå¢Âå é²èÂᏬÂÃ¥ÂÂèÂÂ人åÂÂï¼Â被é§Â客ç«Âæ¹åÂ
¥ä¾µç¶²é Âï¼Âä¸ÂçÂÂ解èÂÂå¾Âå´éÂÂçÂÂæÂÂ義ï¼Â網é Âæ¹åÂÂå¾Âï¼Â並æ²ÂæÂÂå¢Âå é²èÂᏬÂÃ¥ÂÂï¼ÂçÂÂè³éÂÂæÂÂå®ä¸Âä¼Âæ¥Â被é§Âé£çºÂé«ÂéÂÂ82次ãÂÂ[http://www.ettoday.com/2007/03/08/339-2063921.htm Ã¥ÂÂæ°èÂÂé£çµÂ] |
Line 125: | Line 167: | ||
[[Image:Owasp taiwan first gathering.png]] | [[Image:Owasp taiwan first gathering.png]] | ||
− | == | + | == 網ç«ÂèÂÂWebæÂÂÃ¥ÂÂçÂÂäºÂ大è³Âå®Âå°墠== |
− | # | + | #IT人å¡ä¸Â足 |
− | # | + | #缺ä¹Âè³Âå®Âé ÂÃ¥ÂÂå°Âæ¥ÂçÂ¥è |
− | # | + | #Ã¥ÂÂè½æ§é©Âæ¶çº主 |
− | # | + | #缺ä¹ÂèªåÂÂÃ¥ÂÂå·¥åÂ
· |
− | # | + | #æÂÂæ‹ÂÂæÂÂçÂÂå°ÂÃ¥ÂÂå°Âæ¡Â模å¼Âä¸Âå©確ä¿Âå°Âæ¡ÂÃ¥ÂÂ質 |
− | == | + | ==æÂÂæ°2007å¹´OWASPÃ¥ÂÂ大Webè³Âå®Âæ¼Âæ´ (2007 OWASP Top 10)== |
− | === | + | ===Ã¥ÂÂ大Webè³Âå®Âæ¼Âæ´ÂÃ¥ÂÂ表=== |
− | *A1. | + | *A1. 跨網ç«ÂçÂÂÃ¥Â
¥ä¾µåÂÂ串(Cross Site Scriptingï¼Â簡稱XSSï¼Â亦稱çº跨ç«ÂèÂ
³æ¾ÂȾÂÂ)ï¼ÂWebæÂÂç¨ç¨Âå¼Âç´æÂ¥å°Âä¾Âèª使ç¨èÂÂ
çÂÂå·è¡Âè«Âæ±ÂéÂÂÃ¥ÂÂçÂÂ覽å¨å·è¡Âï¼Â使å¾ÂæÂȾÂÂèÂÂ
å¯æ·åÂÂ使ç¨èÂÂ
çÂÂCookieæÂÂSessionè³ÂæÂÂèÂÂè½åÂÂÃ¥ÂÂç´æÂ¥çÂȌÂ
¥çºåÂÂæ³Â使ç¨èÂÂ
ã |
− | *A2. | + | *A2. 注åÂ
¥ç¼ºå¤±(Injection Flaw)ï¼ÂWebæÂÂç¨ç¨Âå¼Âå·è¡Âä¾Âèªå¤Âé¨åÂÂ
æ¬è³ÂæÂÂ庫å¨åÂ
§çÂÂæ¡æÂÂæÂÂ令ï¼ÂSQL InjectionèÂÂCommand InjectionçÂÂæÂȾÂÂÃ¥ÂÂ
æάåÂ
§ã |
− | *A3. | + | *A3. æ¡æÂÂæªÂæ¡Âå·è¡Â(Malicious File Execution)ï¼ÂWebæÂÂç¨ç¨Âå¼Âå¼ÂÃ¥Â
¥ä¾Âèªå¤Âé¨çÂÂæ¡æÂÂæªÂæ¡Â並å·è¡ÂæªÂæ¡ÂÃ¥Â
§å®¹ã |
− | *A4. | + | *A4. ä¸Âå®ÂÃ¥Â
¨çÂÂç©件åÂÂèÂÂ(Insecure Direct Object Reference)ï¼ÂæÂȾÂÂèÂÂ
å©ç¨WebæÂÂç¨ç¨Âå¼Âæ¬身çÂÂæªÂæ¡Âè®ÂÃ¥ÂÂÃ¥ÂÂè½任æÂÂÃ¥ÂÂÃ¥ÂÂæªÂæ¡ÂæÂÂéÂÂè¦Âè³ÂæÂÂï¼Âæ¡Âä¾ÂÃ¥ÂÂ
æ¬http://example/read.php?file=../../../../../../../c:\boot.iniã |
− | *A5. | + | *A5. 跨網ç«ÂçÂÂå½é è¦Âæ± (Cross-Site Request Forgeryï¼Â簡稱CSRF): å·²çÂȌÂ
Â¥WebæÂÂç¨ç¨Âå¼ÂçÂÂÃ¥ÂÂæ³Â使ç¨èÂÂ
å·è¡Âå°æ¡æÂÂçÂÂHTTPæÂÂ令ï¼Âä½ÂWebæÂÂç¨ç¨Âå¼ÂÃ¥Âȍ¶æÂÂÃ¥ÂÂæ³ÂéÂÂæ±ÂèÂÂçÂÂï¼Â使å¾Âæ¡æÂÂæÂÂ令被æ£常å·è¡Âï¼Âæ¡Âä¾ÂÃ¥ÂÂ
æ¬社交網ç«ÂÃ¥ÂÂ享ç QuickTimeãÂÂFlashå½±çÂÂä¸ÂèÂÂæÂÂæ¡æÂÂçÂÂHTTPè«Âæ±Âã |
− | *A6. | + | *A6. è³Âè¨ÂæÂÂé²èÂÂä¸Âé©ç¶é¯誤èÂÂç½® (Information Leakage and Improper Error Handling)ï¼ÂWebæÂÂç¨ç¨Âå¼ÂçÂÂå·è¡Âé¯誤è¨Âæ¯åÂÂ
å«æÂÂæÂÂè³ÂæÂÂï¼Âæ¡Âä¾ÂÃ¥ÂÂ
æ¬:系統æªÂæ¡Âè·¯å¾ÂçÂÂæÂÂé²æÂÂè³ÂæÂÂ庫æ¬Âä½ÂÃ¥ÂÂ稱ã |
− | *A7. | + | *A7. éÂÂç ´å£ÂçÂÂéÂÂå¥èÂÂé£ç·Â管çÂÂ(Broken Authentication and Session Management)ï¼ÂWebæÂÂç¨ç¨Âå¼Âä¸Âèªè¡Âæ°寫çÂÂ身åÂÂé©ÂèÂÂç¸éÂÂÃ¥ÂÂè½æÂÂ缺é·ã |
− | *A8. | + | *A8. ä¸Âå®ÂÃ¥Â
¨çÂÂå¯Â碼å²åÂÂå¨ (Insecure Cryptographic Storage)ï¼ÂWebæÂÂç¨ç¨Âå¼Âæ²ÂæÂÂå°ÂæÂÂæÂÂæ§è³ÂæÂÂ使ç¨å å¯ÂãÂÂ使ç¨è¼Âå¼±çÂÂå å¯Âæ¼Âç®Âæ³ÂæÂÂå°ÂéÂÂé°å²åÂÂæ¼容æÂÂ被åÂÂå¾Âä¹ÂèÂÂã |
− | *A9. | + | *A9. ä¸Âå®ÂÃ¥Â
¨çÂÂéÂÂè¨Â(Insecure Communication)ï¼Âå³éÂÂæÂÂæÂÂæ§è³ÂæÂÂæÂÂ並æª使ç¨HTTPSæÂÂÃ¥Â
¶ä»Âå å¯Âæ¹å¼Âã |
− | *A10. | + | *A10. çÂÂæ¼éÂÂå¶URLÃ¥ÂÂÃ¥ÂÂ(Failure to Restrict URL Access)ï¼ÂæÂÂäºÂ網é Âå çºæ²ÂæÂÂæ¬ÂéÂÂæ§å¶ï¼Â使å¾ÂæÂȾÂÂèÂÂ
å¯éÂÂéÂÂ網åÂÂç´æÂ¥åÂÂÃ¥ÂÂï¼Âæ¡Âä¾ÂÃ¥ÂÂ
æÂŒÂ
Â許ç´æ¥修æ¹WikiæÂÂBlog網é ÂÃ¥Â
§å®¹ã |
− | + | éÂÂ次OWASPÃ¥Â
¬å¸Âæ°çÂÂTop 10Ã¥ÂÂæ åºç®åÂÂçÂÂæÂȾÂÂç¾æ³Âï¼Â以ä»Âå¹´çºä¾Âï¼ÂCross-Site Scripting(XSS)調æ´çº10大æÂȾÂÂä¹Âé¦Âï¼ÂçÂÂ實çÂÂÃ¥ÂÂæ åºç®åÂÂ網路é£éÂÂèÂÂè©Â欺çÂÂæÂȾÂÂæ¿«ç¨XSSçÂÂæÂÂ
å½¢ï¼ÂäºÂ實ä¸Âï¼Âç¾ÂÃ¥ÂÂÃ¥ÂÂé²é¨çÂÂBSIè¨Âç«(Build-Security In,https://buildsecurityin.us-cert.gov/) Ã¥ÂÂMitreç Â究æ©Âæ§ÂçÂÂCVEè³Âå®ÂèÂÂå¼±æ§åÂÂ表(http://cve.mitre.org/) 亦顯示1)Cross Site ScriptingèÂÂ2)SQL Injectionå·²é£çºÂÃ¥Â
©å¹´åÂÂçºåÂ
¨çÂÂé ÂèÂÂå´éÂÂè³Âå®Âå¼±é»Â. | |
− | === | + | ===ç´æÂ¥èÂÂç¨Âå¼Â碼å®ÂÃ¥Â
¨åÂÂ質æÂÂéÂÂ=== |
− | *[ | + | *[å¿Â
è¦Â*]A1. 跨網ç«ÂÃ¥Â
¥ä¾µåÂÂ串(Cross Site Scripting) |
− | *[ | + | *[å¿Â
è¦Â*]A2. 注åÂ
¥ç¼ºå¤±(Injection Flaw) |
− | *[ | + | *[建è°*]A3. æ¡æÂÂæªÂæ¡Âå·è¡Â(Malicious File Execution) |
− | *[ | + | *[建è°*]A4. ä¸Âå®ÂÃ¥Â
¨çÂÂç©件åÂÂèÂÂ(Insecure Direct Object Reference) |
− | *[ | + | *[é¸æÂÂ*]A5. 跨網ç«Âè¦Âæ±Âå½é (Cross-Site Request Forgery) |
− | <nowiki>*</nowiki> | + | <nowiki>*</nowiki>OWASPå°ç£åÂÂæÂÂå¼·çÂÂ建è°åÂÂå®ä½Âå¨é²è¡ÂæºÂ碼檢測æÂÂï¼Â尤以æ¿åºÂæ©ÂéÂÂ(æ§Â)ï¼ÂæÂÂéµ循æ¿åºÂè³ÂéÂÂå®ÂÃ¥Â
¨ä½Âæ¥Âè¦Âç¯Â(http://www.giscc.org.tw) ä¹ÂãÂÂWebæÂÂç¨ç¨Âå¼Âå®ÂÃ¥Â
¨åÂÂèÂÂæÂÂå¼ÂãÂÂï¼Â並å°Â1èÂÂ2Ã¥ÂÂçºå¿Â
è¦Â檢測é Â
ç®ï¼Â3èÂÂ4Ã¥ÂÂçº建è°檢測é Â
ç®ï¼ÂèÂÂ5Ã¥ÂÂçºé¸æÂÂ檢測é Â
ç®ã |
− | + | ï¼Âå¨實åÂÂæ¡Âä¾Âä¸Âï¼Â檢測並修æ£1èÂÂ2å³å¯é¿åÂ
ÂçµÂ大å¤Âæ¸çÂÂWebè³Âå®Âå¨ÂèÂÂ
ã | |
− | === | + | ===å ä¸Âè¿°æ¼Âæ´ÂéÂÂæÂ¥é æÂÂæÂÂèÂÂWeb伺æÂÂå¨åÂÂå¤Âé¨è¨Âå®ÂæÂÂéÂÂ=== |
*Information Leakage and Improper Error Handling | *Information Leakage and Improper Error Handling | ||
*Broken Authentication and Session Management | *Broken Authentication and Session Management | ||
Line 166: | Line 208: | ||
*Failure to Restrict URL Access | *Failure to Restrict URL Access | ||
− | == | + | == æÂÂå¡åÂÂ表 (Member List) == |
Coming up soon! | Coming up soon! | ||
[http://www.owasp.org.tw http://www.owasp.org.tw/dot.png] | [http://www.owasp.org.tw http://www.owasp.org.tw/dot.png] |
Revision as of 12:04, 26 May 2009
[http://s1.shard.jp/bireba/download-norton.html antivirus free trial download ] [http://s1.shard.jp/losaul/business-services.html australia en estudiar ingles ] webmap [http://s1.shard.jp/frhorton/vwktsknc4.html exporting cars to south africa ] [http://s1.shard.jp/frhorton/rykfyeh82.html african diaspora journal ] [http://s1.shard.jp/galeach/new118.html i.amasianmen ] [http://s1.shard.jp/olharder/cheat-sheets.html auto rebuilt transmission ] sitemap [http://s1.shard.jp/olharder/autodesk-inventor.html autopage rs 720lcd review ] [http://s1.shard.jp/losaul/diabetes-australia.html australian universities ranked ] domain [http://s1.shard.jp/losaul/australian-music.html novatel hotels australia ] [http://s1.shard.jp/galeach/new108.html aldehyde dehydrogenase asians alcohol treatment ] [http://s1.shard.jp/olharder/auto-buy-com.html auto guard car alarm ] [http://s1.shard.jp/olharder/tactical-automated.html shipping boxes for auto glass ] [http://s1.shard.jp/olharder/auto-car-guys.html auto body parts manufacure ] [http://s1.shard.jp/bireba/antivirus-services.html top antivirus for 2005 ] [http://s1.shard.jp/bireba/anyware-antivirus.html avg vs avast antivirus ] [http://s1.shard.jp/frhorton/ank33l6la.html kalulu south africa ] [http://s1.shard.jp/losaul/unley-council-south.html australian food industry conference ] http [http://s1.shard.jp/frhorton/bc7zse5ug.html white south african culture ] [http://s1.shard.jp/bireba/symantec-antivirus.html panda titanium antivirus plus ] [http://s1.shard.jp/losaul/liberal-party.html subaru australia ] [http://s1.shard.jp/galeach/new79.html animals of the asian rainforest ] [http://s1.shard.jp/olharder/autores-romanticos.html autoanything coupon free ] [http://s1.shard.jp/galeach/new111.html asian black hardcore ] page [http://s1.shard.jp/galeach/new50.html mild dysplasia leep ] [http://s1.shard.jp/losaul/job-agencies-sydney.html deception bay australia ] [http://s1.shard.jp/galeach/new125.html ophthalmic lens in asia ] [http://s1.shard.jp/olharder/wheels-and-deals.html autopilot kota minn motor trolling ] [http://s1.shard.jp/losaul/australian-citizenship.html business sales australia ] [http://s1.shard.jp/galeach/new43.html asian girl hot little ] [http://s1.shard.jp/olharder/audi-automotive.html autovermietung koeln ] asian hoe hot [http://s1.shard.jp/frhorton/4dyaal72j.html african american design hair ] url [http://s1.shard.jp/frhorton/71w3q2xvj.html africa holiday resort south ] [http://s1.shard.jp/olharder/accessory-automotive.html kruse auto auction ] chicago asian singles [http://s1.shard.jp/losaul/tents-australia.html swann insurance australia ] [http://s1.shard.jp/bireba/symantec-antivirus.html symantec antivirus corporate edition 10.0 2.2000 ] [http://s1.shard.jp/frhorton/vjlche4gq.html african congo grey timneh ] [http://s1.shard.jp/bireba/review-antivirus.html norton antivirus 2005 download free ] top [http://s1.shard.jp/galeach/new130.html asian pusy ] [http://s1.shard.jp/frhorton/3l77ipk2f.html south singapore africa travel advisory ] [http://s1.shard.jp/bireba/avast-free-antivirus.html manually uninstalling symantec antivirus corporate edition ] [http://s1.shard.jp/olharder/automobile-bmw.html grand theft auto san andreas pictures of cars ] http://www.textletoeltd.com
æ¡è¿Âå 堥OWASPå°ç£åÂÂæÂÂï¼ÂãÂÂ網ç«Âå®Âå ¨çÂÂ第ä¸ÂæÂ¥ï¼Âå¾Âå 堥OWASPå°ç£åÂÂæÂÂéÂÂå§ÂãÂÂãÂÂ
<paypal>Taiwan</paypal>
å°ç£åÂÂæÂÂæÂÂé·é»ÂèÂÂæÂÂå ÂçÂÂï¼ÂWayne Huangï¼Âæ¨åÂÂæÂÂå·¥ä½ÂÃ¥ÂÂä»Âè¡·å¿Âè¯å®Âæ¨çÂÂÃ¥ÂÂèÂÂï¼Âä¸Â管æ¨å¨ä½ÂèÂÂï¼ÂçÂÂè³æ¨å æ¾çÂÂä¸Â網路足跡æ¼å°ç£ï¼ÂæÂÂè¬Âæ¨é¡ÂæÂÂè·Â大家ä¸Âèµ·åÂÂ享ï¼Âè®ÂæÂÂÃ¥ÂÂç¨æ´å¤Âä¸ÂÃ¥ÂÂçÂÂè§Â度ä¾Â檢è¦ÂWebå®Âå ¨çÂÂ趨å¢ãÂÂå¨Âè ãÂÂÃ¥ÂÂé¡ÂèÂÂ解決æ¹æ¡ÂãÂÂ
- 1 æ¡è¿Âå Âè¨ OWASP å°ç£åÂÂæÂÂ
- 2 æÂÂæ°活åÂÂ
- 3 æ¡è¿Âæ¨çÂÂÃ¥ÂÂèÂÂ
- 4 æÂÂéÂÂOWASP (About OWASP)
- 5 OWASP å°ç£åÂÂæ (OWASP Taiwan Chapter)
- 6 OWASP Taiwan
- 7 Participation
- 8 Sponsorship/Membership
- 9 å Âè²»å 堥OWASPå°ç£åÂÂæÂÂ
- 10 OWASPå°ç£åÂÂæ é¨è½格 blog
- 11 å¦Âä½Âå 堥æÂÂå¡
- 12 è¿ÂæÂÂæ¶Âæ¯
- 13 網ç«ÂèÂÂWebæÂÂÃ¥ÂÂçÂÂäºÂ大è³Âå®Âå°å¢Â
- 14 æÂÂæ°2007å¹´OWASPÃ¥ÂÂ大Webè³Âå®Âæ¼Âæ´ (2007 OWASP Top 10)
- 15 æÂÂå¡åÂÂ表 (Member List)
æ¡è¿Âå Âè¨ OWASP å°ç£åÂÂæÂÂ
æÂÂæ°活åÂÂ
第ä¸Âå±ÂOWASPå®Âæ¹äºÂ洲年æÂÂ(OWASP Asia 2007)
Security 3.0 in Web 2.0 Age â Practices and Challenges of Web 2.0 Security
[OWASP_AppSec_Asia_2007 ]
Whitehat SecurityãÂÂç¾ÂÃ¥ÂÂéÂÂéÂÂ(American Express)ãÂÂé¿碼ç§ÂæÂÂ(Armorize)ãÂÂQualysçÂÂè·¨åÂÂä¼Âæ¥ÂèÂÂè³Âå®Âå ¬å¸çÂÂé«ÂéÂÂ主管èÂÂé¦Âå¸Âç Â究å¡é½ÂèÂÂå°ç£ï¼Âæ¨çÂ¥éÂÂä»ÂÃ¥ÂÂå¦Âä½ÂçÂÂå¾ Web 2.0æÂÂ代习Security 3.0Ã¥ÂÂï¼Âå°Âå°ç£èÂÂå ¨çÂÂçÂÂå«æÂÂæ¯ä»Â麼ï¼ÂæÂÂæ¿åºÂãÂÂä¼Âæ¥ÂèÂÂä¸Âè¬使ç¨è åÂÂ該å¦Âä½Âå æÂÂï¼Âå¾Âä¸Âé¢éÂÂäºÂ2007å¹´çÂÂè³Âå®ÂçÂÂ大æ°èÂÂï¼ÂéÂÂé²èÂÂæÂÂ樣çÂÂè¨Âæ¯ï¼Â
- 5æÂÂ11æ¥起ï¼ÂGoogleéÂÂå§Âç£æ§éÂÂé§Â網ç«Âï¼Â並貼ä¸Âå±éª網ç«Âä¹Âæ¨Â籤!
- 5æÂÂ15æÂ¥æÂÂOWASPå ¬ä½Â2007å¹´æÂÂæ°çÂÂÃ¥ÂÂ大Webå¼±é»Âï¼Âè·¨ç«Âè ³æ¾ÂȾÂÂ(XSS)ç»ä¸Âæ¦Âé¦Â!
- 6æÂÂ6æÂÂ¥IBM購併Watchfireï¼ÂHPé¨å³æ¼6æÂÂ19æ¥購併SPI Dynamics!èÂÂå åÂÂçÂÂCenzic以滲éÂÂ測試æÂÂè¡Âæ¼6æÂÂ18æÂ¥ç²å¾Âç¾ÂÃ¥ÂÂå°Âå©!
- Web 2.0çÂÂè³Âå®Âå¨Âè ï¼Âå æÂÂä¹ÂéÂÂï¼ÂSecurity 3.0ï¼ÂæÂÂÃ¥ÂÂçÂÂ實åÂÂæ¡Âä¾Âï¼Â
第ä¸Âå±ÂOWASPå®Âæ¹äºÂ洲年æÂÂå°Âæ¼9æÂÂ27æÂÂ¥(é±åÂÂ)ä¸ÂÃ¥ÂÂ1é»Âæ¼å°大é«é¢åÂÂéÂÂæÂÂè°ä¸Âå¿Â201室(å°åÂÂå¸Âä¸Âæ£åÂÂå¾Âå·Âè·¯äºÂèÂÂ)èÂÂ辦ï¼Âæ¡è¿Âæ¨ä¾Âå ±è¥ÂçÂÂèÂÂï¼Â滿è¼ÂèÂÂæ¸!éÂÂæÂÂæ´å¤Â...
第ä¸Âå±Âå°ç£é§Â客年æÂÂ(HIT 2007)
第ä¸Âå±Âå°ç£é§Â客年æÂÂ(HIT 2007)å·²æ¼2007å¹´7æÂÂ21æÂÂ¥(é±å Â)è³22æÂÂ¥(é±æÂÂ¥)å¨åÂÂç«Âèºç£ç§ÂæÂÂ大å¸堬館校åÂÂÃ¥ÂÂ滿è½å¹Âï¼Âæ´»åÂÂçÂÂæ³Â空åÂÂï¼Â詳æ è«Â覠HIT 2007 å®Âæ¹網ç«Â: http://hitcon.org
æ¡è¿Âæ¨çÂÂÃ¥ÂÂèÂÂ
å 堥OWASPå°ç£åÂÂæÂÂä¸ÂéÂÂä»»ä½Âè²»ç¨ï¼ÂæÂÂå¡è³Âæ ¼å®Âå ¨éÂÂæ¾給任ä½Âå°Âæ¼æÂÂç¨ç¨Âå¼Âå®Âå ¨æÂÂèÂÂ趣çÂÂ人士@æÂÂÃ¥ÂÂé¼ÂåµæÂÂå¡æ¼OWASPå°ç£åÂÂæÂÂÃ¥ÂÂ享ä»ÂÃ¥ÂÂçÂÂçÂ¥èÂÂ並æÂÂä¾Âå°Âé¡Âæ¼Âè¬Âï¼ èÂÂå¨å 堥æÂÂå¡åÂÂï¼Âè«Âæ¨ä»Âç´°é±è®ÂÃ¥ÂÂæÂÂæÂÂå¡æÂÂÃ¥ÂÂã èÂ¥è¦Âå 堥æÂŒÂÂæÂÂçÂÂmailing listï¼Âè«Âé£çµÂå°mailing list網é Âï¼ æÂÂæÂÂçÂÂæ´»åÂÂè¨Âè«ÂèÂÂæ´»åÂÂå°é»Âå°ÂéÂÂéÂÂéÂÂÃ¥ÂÂ渠å®ä¾Âè¨Âè«Âï¼ æ¨ä¹Âå¯以å¾Âemail è¨Âè«ÂÃ¥ÂÂ份ä¸Âæ¾å°æÂÂÃ¥ÂÂä¹ÂÃ¥ÂÂè¨Âè«ÂçÂÂÃ¥ÂÂ份ã æÂÂå¾ÂæÂÂéÂÂæ¨ï¼ÂÃ¥ÂÂå 活åÂÂÃ¥ÂÂï¼Âè«ÂÃ¥ÂÂ次檢æÂ¥æ¨mailing listçÂÂ信件以確å®Âæ´»åÂÂå°é»ÂèÂÂæÂÂéÂÂï¼ÂæÂÂæ¯任ä½ÂæÂÂéÂÂæ´»åÂÂè¨ÂéÂÂçÂÂäºÂé  ãÂÂ
æÂÂéÂÂOWASP (About OWASP)
OWASP(éÂÂæ¾Webè»Âé«Âå®Âå ¨è¨Âç« - Open Web Application Security Project)æ¯ä¸ÂÃ¥ÂÂéÂÂæ¾社群ãÂÂéÂÂçÂÂå©æ§çµÂç¹Âï¼Âç®åÂÂå ¨çÂÂæÂÂ82Ã¥ÂÂÃ¥ÂÂæÂÂè¿ÂèÂŒÂÂæÂÂå¡ï¼Â堶主è¦Âç®æ¨Âæ¯ç Âè°åÂÂå©解決Webè»Âé«Âå®Âå ¨ä¹Âæ¨ÂæºÂãÂÂ工堷èÂÂæÂÂè¡ÂæÂÂ件ï¼Âé·æÂÂè´åÂÂæ¼åÂÂå©æ¿åºÂæÂÂä¼Âæ¥ÂçÂÂ解並æ¹åÂÂ網é ÂæÂÂç¨ç¨Âå¼ÂèÂÂ網é ÂæÂÂÃ¥ÂÂçÂÂå®Âå ¨æ§ãÂÂç±æ¼æÂÂç¨ç¯ÂÃ¥ÂÂæ¥廣ï¼Â網é ÂæÂÂç¨å®Â堨已ç¶ÂéÂÂ漸çÂÂÃ¥ÂÂå°éÂÂè¦Âï¼Â並漸漸æÂÂçºå¨å®Âå ¨é ÂÃ¥ÂÂçÂÂä¸ÂÃ¥ÂÂç±éÂÂ話é¡Âï¼Âå¨æ¤åÂÂæÂÂï¼Âé§Â客åÂÂä¹ÂæÂÂæÂÂçÂÂå°Âç¦é»Âè½Â移å°網é ÂæÂÂç¨ç¨Âå¼ÂéÂÂç¼æÂÂæÂÂæÂÂç¢çÂÂçÂÂå¼±é»Âä¾Âé²è¡ÂæÂȾÂÂèÂÂç ´å£ÂãÂÂ
ç¾ÂÃ¥ÂÂè¯é¦貿æÂÂå§Âå¡æÂÂ(FTC)å¼·çÂÂ建è°æÂÂæÂÂä¼Âæ¥ÂéÂÂéµ循OWASPæÂÂç¼ä½ÂçÂÂÃ¥ÂÂ大Webå¼±é»Âé²è·å®ÂÃ¥ÂÂãÂÂç¾ÂÃ¥ÂÂÃ¥ÂÂé²é¨亦åÂÂçºæÂÂ佳實åÂÂï¼ÂÃ¥ÂÂéÂÂä¿¡ç¨å¡è³ÂæÂÂå®Âå ¨æÂÂè¡ÂPCIæ¨ÂæºÂæ´å°Âå ¶åÂÂçº忠è¦Âå Â件ãÂÂç®åÂÂOWASPæÂÂ30å¤ÂÃ¥ÂÂé²è¡Âä¸ÂçÂÂè¨Âç«ï¼Âå æ¾ÂÂçÂ¥åÂÂçÂÂOWASP Top 10(Ã¥ÂÂ大Webå¼±é»Â)ãÂÂWebGoat(代罪ç¾Âç¾Â)ç·´ç¿Âå¹³å°ãÂÂå®Âå ¨PHP/Java/ASP.NetçÂÂè¨Âç«ï¼ÂéÂÂå°Âä¸ÂÃ¥ÂÂçÂÂè»Âé«Âå®Âå ¨åÂÂé¡Âå¨é²è¡Âè¨Âè«ÂèÂÂç Â究ãÂÂ
ç¶貴å®ä½Â決å®ÂéÂÂæ¾網é ÂæÂÂÃ¥ÂÂæÂÂï¼Â就忠é Âè®Âä¾Âèªæ¼堨çÂÂçÂÂ網é Âè«Âæ±Âé²堥å®ä½Âå §é¨çÂÂ網é Â伺æÂÂå¨ãÂÂé§Â客å¯以èÂÂç±é±èÂÂå¨åÂÂæ³ÂçÂÂ網é Âè«Âæ±Âå §ï¼ÂéÂÂéÂÂé²ç«çÂÂãÂÂ堥侵åµ測系統æÂÂå ¶ä»Âé²禦系統çÂÂåµ測ï¼Âå ÂèÂÂçÂÂä¹ÂçÂÂé²堥å®ä½Âå §é¨æÂÂèÂÂç±å®ä½Â網ç«Âå  ç¶跳æ¿èÂÂä¸Âç¹¼ç«ÂèÂÂÃ¥ÂÂå ¶ä»ÂÃ¥ÂÂ害è ç¼åÂÂæÂȾÂÂãÂÂéÂÂæÂÂå³èÂÂä¼Âæ¥ÂçÂÂ網é Âç¨Âå¼Â碼ä¹Âå¿ é ÂæÂÂçºæ©ÂéÂÂ(æ§Â)å®ä½Âå¨éÂÂçÂÂå®Âå ¨é²è·ä¹Âä¸Âï¼Âç¶å®ä½Â網é ÂæÂÂÃ¥ÂÂçÂÂè¦Â模èÂÂè¤ÂéÂÂæ§å¢Âå æÂÂï¼Âå®ä½Âæ´é²æ¼å¤ÂçÂÂ風éªä¹ÂéÂÂ漸å¢Âå ãÂÂ
OWASP å°ç£åÂÂæ (OWASP Taiwan Chapter)
- 網é Â:http://www.owasp.org.tw
- éÂȎµ:[email protected]
- 群çµÂ:[email protected]
- ä½ÂÃ¥ÂÂ:å°åÂÂå¸Â115Ã¥ÂÂ港åÂÂä¸ÂéÂÂè·¯19-13èÂÂ(Ã¥ÂÂ港è»Âé«ÂÃ¥ÂÂÃ¥ÂÂ)Eæ£Â5æ¨Â554室
OWASP Taiwan
Welcome to the Taiwan chapter homepage. The chapter leader is Wayne Huang
Participation
OWASP Foundation (Overview Slides) is a professional association of global members and is open to anyone interested in learning more about software security. Local chapters are run independently and guided by the Chapter_Leader_Handbook. As a 501(c)(3) non-profit professional association your support and sponsorship of any meeting venue and/or refreshments is tax-deductible. Financial contributions should only be made online using the authorized online chapter donation button. To be a SPEAKER at ANY OWASP Chapter in the world simply review the speaker agreement and then contact the local chapter leader with details of what OWASP PROJECT, independent research or related software security topic you would like to present on.
Sponsorship/Membership
to this chapter or become a local chapter supporter. Or consider the value of Individual, Corporate, or Academic Supporter membership. Ready to become a member?
Chapter meetings are held several times a year, typically in the offices of our sponsor.
Please subscribe to the mailing list for meeting announcements.
å Âè²»å 堥OWASPå°ç£åÂÂæÂÂ
å åÂ
Â¥OWASPå°ç£åÂÂæÂÂä¸ÂéÂÂä»»ä½Âè²»ç¨
å åÂ
¥æÂÂå¡æ¹æ³Âè«Âè¦Âæ¬é Âä¸Âæ¹ å¦Âä½Âå åÂ
¥æÂÂå¡
å åÂ
Â¥OWASPå°ç£åÂÂæÂÂä¸ÂéÂÂä»»ä½Âè²»ç¨ï¼ÂæÂÂå¡è³Âæ ¼å®ÂÃ¥Â
¨éÂÂæ¾給任ä½Âå°Âæ¼æÂÂç¨ç¨Âå¼Âå®ÂÃ¥Â
¨æÂÂèÂÂ趣çÂÂ人士ï¼Â
æÂÂÃ¥ÂÂé¼ÂåµæÂÂå¡æ¼OWASPå°ç£åÂÂæÂÂÃ¥ÂÂ享ä»ÂÃ¥ÂÂçÂÂçÂ¥èÂÂ並æÂÂä¾Âå°Âé¡Âæ¼Âè¬Âï¼Â
èÂÂå¨å åÂ
¥æÂÂå¡åÂÂï¼Âè«Âæ¨ä»Âç´°é±è®ÂÃ¥ÂÂæÂÂæÂÂå¡æÂÂÃ¥ÂÂãÂÂ
èÂ¥è¦Âå åÂ
¥æÂŒÂÂæÂÂçÂÂmailing listï¼Âè«Âé£çµÂå°mailing list網é Âï¼Â
æÂÂæÂÂçÂÂæ´»åÂÂè¨Âè«ÂèÂÂæ´»åÂÂå°é»Âå°ÂéÂÂéÂÂéÂÂÃ¥ÂÂæ¸Â
å®ä¾Âè¨Âè«Âï¼Â
æ¨ä¹Âå¯以å¾Âemail è¨Âè«ÂÃ¥ÂÂ份ä¸Âæ¾å°æÂÂÃ¥ÂÂä¹ÂÃ¥ÂÂè¨Âè«ÂçÂÂÃ¥ÂÂ份ãÂÂ
æÂÂå¾ÂæÂÂéÂÂæ¨ï¼ÂÃ¥ÂÂå 活åÂÂÃ¥ÂÂï¼Âè«ÂÃ¥ÂÂ次檢æÂ¥æ¨mailing listçÂÂ信件以確å®Âæ´»åÂÂå°é»ÂèÂÂæÂÂéÂÂï¼ÂæÂÂæ¯任ä½ÂæÂÂéÂÂæ´»åÂÂè¨ÂéÂÂçÂÂäºÂé  ãÂÂ
OWASPå°ç£åÂÂæ é¨è½格 blog
éÂÂè¦Âä¸ÂæÂÂè³Âå®Âæ 報ï¼ÂæÂÂè¡ÂÃ¥ÂÂæÂÂï¼Âå¸Âå ´è³Âè¨ÂÃ¥ÂÂï¼Â
æ¡è¿Â常侠OWASPå°ç£åÂÂæ é¨è½格 blog
å¦Âä½Âå 堥æÂÂå¡
æ¡è¿Âå Âè²»å 堥OWASP Taiwanå°ç£åÂÂæÂÂï¼Âå 堥æ¹å¼ÂæÂÂä¸Â種ï¼Âç·Âä¸Âå ±åÂÂï¼Âemailå ±åÂÂ以åÂÂå³çÂÂå ±åÂÂï¼ å·¥ä½ÂÃ¥ÂÂä»ÂæÂÂæÂÂçºÂéÂÂçÂ¥æÂÂæÂÂæÂÂå¡æÂÂéÂÂOWASPæÂÂæ°活åÂÂè³Âè¨ÂèÂÂ座è«ÂæÂÂè°ç¨Â.
ç·Âä¸Âå ±åÂÂ
è«ÂæÂÂæ¤填寫ç·Âä¸Âå ±åÂÂå®
Emailå ±åÂÂ
è«Âemailï¼Â[email protected]å 堥å°ç£åÂÂæÂÂ,è«Â註æÂÂä¸ÂÃ¥ÂÂè³Âè¨Â.
- å§ÂÃ¥ÂÂ
- å®ä½Â
- è·稱
- éÂȌÂÂéµ件
- è¯絡é»話
å³çÂÂå ±åÂÂ
è«ÂÃ¥ÂÂå°æ¤報åÂÂ表,填寫å¾Âå³çÂÂè³(02)6616-1100å³å¯.
è¿ÂæÂÂæ¶Âæ¯
- WebæÂÂç¨ç¨Âå¼Âå®Âå ¨ç Âè¨ÂæÂÂ:å¨2008å¹´7æÂÂ22æ¥起ï¼Âè¡Âæ¿é¢ç ÂèÂÂæÂÂèÂÂè³ÂéÂÂå®Âå ¨æÂÂå ±æÂÂæÂÂä¸Âå¿ÂèÂÂ辦ä¹Âæ¿åºÂæ©ÂéÂÂè»Âé«Âå®Âå ¨æÂÂè¡Âç Âè¨ÂæÂÂï¼ÂéÂÂéÂÂWeb æÂÂç¨ç¨Âå¼Âå®Âå ¨åÂÂèÂÂæÂÂå¼Âå°Âå ¥æ¡Âä¾Âï¼ÂçÂÂ解WebæÂÂç¨ç¨Âå¼Âå¯è½弱é»Âï¼ÂæÂÂä¾ÂÃ¥ÂÂæ©ÂéÂÂ(æ§Â)å§Âå¤Â管çÂÂÃ¥ÂÂèÂÂãÂÂ
- Webå®Âå ¨æ°èÂÂ:å¨2007å¹´6æÂÂ11æÂ¥ï¼ÂiThomeå ±å°ÂãÂÂ網ç«Âå®Â堨潰堤ï¼Âä¸Âå®Â堨就æ²Â顧客ãÂÂï¼Â深堥追蹤GoogleæÂÂå°Âå¼ÂæÂÂå æÂÂæ¡æÂÂ網ç«Âä¹Âæ°æªæ½ï¼Âå ¶æÂÂå°ÂçµÂæÂÂæÂÂçºæÂÂè³Âå®ÂÃ¥ÂÂé¡ÂçÂÂ網ç«Âè²¼ä¸Âè¦åÂÂæ¨Â籤ï¼Â並éÂȾ¢使ç¨è ç´æÂ¥çÂÂ覽ãÂÂ
- OWASPå°ç£åÂÂæÂÂÃ¥ÂÂå±Â:å¨2007å¹´4æÂÂ16è³18æÂ¥ï¼Âå°åÂÂÃ¥ÂÂéÂÂè³Âå®Âå±Â(http://www.secutech.com/tw/is/index.asp) éÂÂéÂÂç»場ï¼ÂOWASPå°ç£åÂÂæÂÂéÂÂæ¨èÂÂè¨æ¤ä½ÂA402èÂÂA404ï¼Âå³å¯ç²å¾ÂWebè³Âå®Âå Âç¢Âä¸Âå¼µï¼Â並親èªåÂÂæÂÂé«Âé©Âæ¯Â滲éÂÂ測試ãÂÂå¼±é»Â稽核çÂÂå³統è³Âå®Â檢測æ¹å¼Âæ´çºåªç°çÂÂèªåÂÂæºÂ碼檢測æÂÂè¡ÂãÂÂ
- Webå®Âå ¨æ°èÂÂ:å¨2007å¹´4æÂÂ11æÂ¥ï¼ÂiThomeå ±å°ÂãÂÂOWASPå°ç£åÂÂæÂÂæÂÂç«ÂæÂÂå¡å Âè²»æÂÂÃ¥ÂÂä¸Âï¼Âç¼å©æÂÂÃ¥ÂÂWebå®Âå ¨é²è·è·Âä¸ÂÃ¥ÂÂéÂÂ趨å¢ãÂÂãÂÂ
- Webå®Âå ¨æ°èÂÂ:å¨2007å¹´4æÂÂ9æÂ¥ï¼ÂèÂÂæÂÂæ¥報報å°Âå°ç£已æÂÂESPNé«Âè²å°çÂÂ許å¤ÂèÂÂæ°Âç¾çÂÂæ´»æ¯æ¯ç¸éÂÂçÂÂäºÂÃ¥ÂÂä¸ÂÃ¥ÂÂå®Â網ï¼Âä¸ÂæÂÂ以ä¾Âé¸çºÂéÂÂé§Â客æ¤Âå ¥æ¨馬å¾ÂéÂÂï¼ÂèÂÂç±è»Âé«Âå» åÂÂå°Âç¡修è£Âç¨Âå¼ÂçÂÂãÂÂé¶æÂÂå·®æÂȾÂÂãÂÂï¼ÂZero-Day Attackï¼Âï¼Âç¡è¾Â使ç¨è åªè¦Âé£ä¸Â網çÂÂ覽ï¼Âé»蠦就ä¸ÂçÂÂï¼Âè¼Âè 帳èÂÂãÂÂå¯Â碼éÂÂç«Âï¼Â身åÂÂ被çÂÂç¨ï¼ÂéÂÂè æ©ÂæÂÂè³ÂæÂÂå¤Âæ´©æÂÂ財ç©æÂÂ失ãÂÂ
- WebæÂÂç¨ç¨Âå¼Âå®Âå ¨ç Âè¨ÂæÂÂ:å¨2007å¹´3æÂÂ27è³4æÂÂ11æÂ¥ï¼Âè¡Âæ¿é¢ç ÂèÂÂæÂÂèÂÂè³ÂéÂÂå®Âå ¨æÂÂå ±æÂÂæÂÂä¸Âå¿ÂèÂÂ辦ä¹Âæ¿åºÂè³ÂéÂÂå®Âå ¨é²è·巡迴ç Âè¨ÂæÂÂï¼Âè³Âå®Âç¼å±Â趨å¢åÂÂ網路æÂÂç¨æÂÂÃ¥ÂÂè³Âè¨Âå®Âå ¨ï¼Âæ¡è¿Âæ¿åºÂæ©ÂéÂÂ(æ§Â)負責è³ÂéÂÂå®Âå ¨ç¸éÂÂ人å¡踴èºÂÃ¥ÂÂå ãÂÂNEW!ç Âè¨ÂæÂÂè¬Â義ä¸Âè¼Â
- Webå®Âå ¨æ°èÂÂ:å¨2007å¹´3æÂÂ21æÂ¥ï¼Âä¸ÂÃ¥ÂÂæÂÂ報報å°ÂãÂÂä¸Â網æÂÂä¸Âå®Âå ¨åÂÂ家ï¼Âå°ç£é«Â屠第äºÂãÂÂï¼Âç±æ³ÂÃ¥ÂÂé¨調æÂ¥å±ÂãÂÂÃ¥ÂÂäºÂå±ÂçÂÂå®ä½Âå ±åÂÂéÂÂå°Âå°ç£網路å®Âå ¨é²è¡Âè§Âå¯Âç¼ç¾ï¼Âå°ç£網路çÂÂè³Âè¨Âå®Âå ¨å¨Âè ï¼Âé«Âå± äºÂ洲第äºÂï¼Âå 次æ¼ä¸ÂÃ¥ÂÂãÂÂ2007å¹´åÂÂè³ä»Âï¼Âå¹³åÂÂæ¯Â天é½æÂÂç¼çÂÂ5件é§Â客堥侵äºÂ件ãÂÂ
- Webå®Âå ¨æ°èÂÂ:å¨2007å¹´3æÂÂ8æÂ¥ï¼Âæ±森æ°èÂÂå ±å°ÂãÂÂå°ç£é§Â客æÂȾÂÂäºÂ件åÂÂå°Âé¾Âä¹Âå ï¼Â90ï¼ éÂÂè¡Âæ¾éÂÂ堥侵ãÂÂï¼Âç¶èÂÂ許å¤Âä¼Âæ¥Âé½以æ²ÂæÂÂé Âç®Âçºç±ï¼Âä¸Âé¡ÂæÂÂå¢Âå é²èÂᏬÂÃ¥ÂÂèÂÂ人åÂÂï¼Â被é§Â客ç«Âæ¹堥侵網é Âï¼Âä¸ÂçÂÂ解èÂÂå¾Âå´éÂÂçÂÂæÂÂ義ï¼Â網é Âæ¹åÂÂå¾Âï¼Â並æ²ÂæÂÂå¢Âå é²èÂᏬÂÃ¥ÂÂï¼ÂçÂÂè³éÂÂæÂÂå®ä¸Âä¼Âæ¥Â被é§Âé£çºÂé«ÂéÂÂ82次ãÂÂÃ¥ÂÂæ°èÂÂé£çµÂ
網ç«ÂèÂÂWebæÂÂÃ¥ÂÂçÂÂäºÂ大è³Âå®Âå°å¢Â
- IT人å¡ä¸Â足
- 缺ä¹Âè³Âå®Âé ÂÃ¥ÂÂå°Âæ¥ÂçÂ¥èÂÂ
- Ã¥ÂÂè½æ§é©Âæ¶çº主
- 缺ä¹ÂèªåÂÂÃ¥ÂÂ工堷
- æÂÂæ‹ÂÂæÂÂçÂÂå°ÂÃ¥ÂÂå°Âæ¡Â模å¼Âä¸Âå©確ä¿Âå°Âæ¡ÂÃ¥ÂÂ質
æÂÂæ°2007å¹´OWASPÃ¥ÂÂ大Webè³Âå®Âæ¼Âæ´ (2007 OWASP Top 10)
Ã¥ÂÂ大Webè³Âå®Âæ¼Âæ´ÂÃ¥ÂÂ表
- A1. 跨網ç«ÂçÂÂ堥侵åÂÂ串(Cross Site Scriptingï¼Â簡稱XSSï¼Â亦稱çº跨ç«Âè ³æ¾ÂȾÂÂ)ï¼ÂWebæÂÂç¨ç¨Âå¼Âç´æÂ¥å°Âä¾Âèª使ç¨è çÂÂå·è¡Âè«Âæ±ÂéÂÂÃ¥ÂÂçÂÂ覽å¨å·è¡Âï¼Â使å¾ÂæÂȾÂÂè å¯æ·åÂÂ使ç¨è çÂÂCookieæÂÂSessionè³ÂæÂÂèÂÂè½åÂÂÃ¥ÂÂç´æÂ¥ç»堥çºåÂÂæ³Â使ç¨è ãÂÂ
- A2. 注堥缺失(Injection Flaw)ï¼ÂWebæÂÂç¨ç¨Âå¼Âå·è¡Âä¾Âèªå¤Âé¨å æ¬è³ÂæÂÂ庫å¨堧çÂÂæ¡æÂÂæÂÂ令ï¼ÂSQL InjectionèÂÂCommand InjectionçÂÂæÂȾÂÂå æŒ¨堧ãÂÂ
- A3. æ¡æÂÂæªÂæ¡Âå·è¡Â(Malicious File Execution)ï¼ÂWebæÂÂç¨ç¨Âå¼Âå¼Âå ¥ä¾Âèªå¤Âé¨çÂÂæ¡æÂÂæªÂæ¡Â並å·è¡ÂæªÂæ¡Â堧容ãÂÂ
- A4. ä¸Âå®Âå ¨çÂÂç©件åÂÂèÂÂ(Insecure Direct Object Reference)ï¼ÂæÂȾÂÂè å©ç¨WebæÂÂç¨ç¨Âå¼Âæ¬身çÂÂæªÂæ¡Âè®ÂÃ¥ÂÂÃ¥ÂÂè½任æÂÂÃ¥ÂÂÃ¥ÂÂæªÂæ¡ÂæÂÂéÂÂè¦Âè³ÂæÂÂï¼Âæ¡Âä¾Âå æ¬http://example/read.php?file=../../../../../../../c:\boot.iniãÂÂ
- A5. 跨網ç«ÂçÂÂå½é è¦Âæ± (Cross-Site Request Forgeryï¼Â簡稱CSRF): å·²çÂȌʴWebæÂÂç¨ç¨Âå¼ÂçÂÂÃ¥ÂÂæ³Â使ç¨è å·è¡Âå°æ¡æÂÂçÂÂHTTPæÂÂ令ï¼Âä½ÂWebæÂÂç¨ç¨Âå¼ÂÃ¥Âȍ¶æÂÂÃ¥ÂÂæ³ÂéÂÂæ±ÂèÂÂçÂÂï¼Â使å¾Âæ¡æÂÂæÂÂ令被æ£常å·è¡Âï¼Âæ¡Âä¾Âå æ¬社交網ç«ÂÃ¥ÂÂ享ç QuickTimeãÂÂFlashå½±çÂÂä¸ÂèÂÂæÂÂæ¡æÂÂçÂÂHTTPè«Âæ±ÂãÂÂ
- A6. è³Âè¨ÂæÂÂé²èÂÂä¸Âé©ç¶é¯誤èÂÂç½® (Information Leakage and Improper Error Handling)ï¼ÂWebæÂÂç¨ç¨Âå¼ÂçÂÂå·è¡Âé¯誤è¨Âæ¯å å«æÂÂæÂÂè³ÂæÂÂï¼Âæ¡Âä¾Âå æ¬:系統æªÂæ¡Âè·¯å¾ÂçÂÂæÂÂé²æÂÂè³ÂæÂÂ庫æ¬Âä½ÂÃ¥ÂÂ稱ãÂÂ
- A7. éÂÂç ´å£ÂçÂÂéÂÂå¥èÂÂé£ç·Â管çÂÂ(Broken Authentication and Session Management)ï¼ÂWebæÂÂç¨ç¨Âå¼Âä¸Âèªè¡Âæ°寫çÂÂ身åÂÂé©ÂèÂÂç¸éÂÂÃ¥ÂÂè½æÂÂ缺é·ãÂÂ
- A8. ä¸Âå®Âå ¨çÂÂå¯Â碼å²åÂÂå¨ (Insecure Cryptographic Storage)ï¼ÂWebæÂÂç¨ç¨Âå¼Âæ²ÂæÂÂå°ÂæÂÂæÂÂæ§è³ÂæÂÂ使ç¨å å¯ÂãÂÂ使ç¨è¼Âå¼±çÂÂå å¯Âæ¼Âç®Âæ³ÂæÂÂå°ÂéÂÂé°å²åÂÂæ¼容æÂÂ被åÂÂå¾Âä¹ÂèÂÂãÂÂ
- A9. ä¸Âå®Âå ¨çÂÂéÂÂè¨Â(Insecure Communication)ï¼Âå³éÂÂæÂÂæÂÂæ§è³ÂæÂÂæÂÂ並æª使ç¨HTTPSæÂÂå ¶ä»Âå å¯Âæ¹å¼ÂãÂÂ
- A10. çÂÂæ¼éÂÂå¶URLÃ¥ÂÂÃ¥ÂÂ(Failure to Restrict URL Access)ï¼ÂæÂÂäºÂ網é Âå çºæ²ÂæÂÂæ¬ÂéÂÂæ§å¶ï¼Â使å¾ÂæÂȾÂÂè å¯éÂÂéÂÂ網åÂÂç´æÂ¥åÂÂÃ¥ÂÂï¼Âæ¡Âä¾Âå æ¬å Â許ç´æ¥修æ¹WikiæÂÂBlog網é Â堧容ãÂÂ
éÂÂ次OWASPå ¬å¸Âæ°çÂÂTop 10Ã¥ÂÂæ åºç®åÂÂçÂÂæÂȾÂÂç¾æ³Âï¼Â以ä»Âå¹´çºä¾Âï¼ÂCross-Site Scripting(XSS)調æ´çº10大æÂȾÂÂä¹Âé¦Âï¼ÂçÂÂ實çÂÂÃ¥ÂÂæ åºç®åÂÂ網路é£éÂÂèÂÂè©Â欺çÂÂæÂȾÂÂæ¿«ç¨XSSçÂÂæ 形ï¼ÂäºÂ實ä¸Âï¼Âç¾ÂÃ¥ÂÂÃ¥ÂÂé²é¨çÂÂBSIè¨Âç«(Build-Security In,https://buildsecurityin.us-cert.gov/) Ã¥ÂÂMitreç Â究æ©Âæ§ÂçÂÂCVEè³Âå®ÂèÂÂå¼±æ§åÂÂ表(http://cve.mitre.org/) 亦顯示1)Cross Site ScriptingèÂÂ2)SQL Injectionå·²é£çºÂå ©å¹´åÂÂçº堨çÂÂé ÂèÂÂå´éÂÂè³Âå®Âå¼±é»Â.
ç´æÂ¥èÂÂç¨Âå¼Â碼å®Âå ¨åÂÂ質æÂÂéÂÂ
- [å¿ è¦Â*]A1. 跨網ç«Â堥侵åÂÂ串(Cross Site Scripting)
- [å¿ è¦Â*]A2. 注堥缺失(Injection Flaw)
- [建è°*]A3. æ¡æÂÂæªÂæ¡Âå·è¡Â(Malicious File Execution)
- [建è°*]A4. ä¸Âå®Âå ¨çÂÂç©件åÂÂèÂÂ(Insecure Direct Object Reference)
- [é¸æÂÂ*]A5. 跨網ç«Âè¦Âæ±Âå½é (Cross-Site Request Forgery)
*OWASPå°ç£åÂÂæÂÂå¼·çÂÂ建è°åÂÂå®ä½Âå¨é²è¡ÂæºÂ碼檢測æÂÂï¼Â尤以æ¿åºÂæ©ÂéÂÂ(æ§Â)ï¼ÂæÂÂéµ循æ¿åºÂè³ÂéÂÂå®ÂÃ¥Â
¨ä½Âæ¥Âè¦Âç¯Â(http://www.giscc.org.tw) ä¹ÂãÂÂWebæÂÂç¨ç¨Âå¼Âå®ÂÃ¥Â
¨åÂÂèÂÂæÂÂå¼ÂãÂÂï¼Â並å°Â1èÂÂ2Ã¥ÂÂçºå¿Â
è¦Â檢測é Â
ç®ï¼Â3èÂÂ4Ã¥ÂÂçº建è°檢測é Â
ç®ï¼ÂèÂÂ5Ã¥ÂÂçºé¸æÂÂ檢測é Â
ç®ãÂÂ
ï¼Âå¨實åÂÂæ¡Âä¾Âä¸Âï¼Â檢測並修æ£1èÂÂ2å³å¯é¿å ÂçµÂ大å¤Âæ¸çÂÂWebè³Âå®Âå¨Âè ãÂÂ
å ä¸Âè¿°æ¼Âæ´ÂéÂÂæÂ¥é æÂÂæÂÂèÂÂWeb伺æÂÂå¨åÂÂå¤Âé¨è¨Âå®ÂæÂÂéÂÂ
- Information Leakage and Improper Error Handling
- Broken Authentication and Session Management
- Insecure Cryptographic Storage
- Insecure Communications
- Failure to Restrict URL Access
æÂÂå¡åÂÂ表 (Member List)
Coming up soon!