This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org
Difference between revisions of "OWASP Encoder Comparison Reference Project"
(33 intermediate revisions by 2 users not shown) | |||
Line 1: | Line 1: | ||
=Main= | =Main= | ||
− | <div style="width:100%;height: | + | <!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --> |
− | + | <div style="width:100%;height:100px;border:0,margin:0;overflow: hidden;">[[Image:OWASP Inactive Banner.jpg|800px| link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Inactive_Projects]] </div> | |
− | |||
− | |||
− | |||
==OWASP Encoder Comparison Reference Project== | ==OWASP Encoder Comparison Reference Project== | ||
− | The OWASP | + | Libraries and frameworks encode ASCII characters differently. The OWASP Enterprise Security API (ESAPI) is the reference implementation for the most comprehensive and secure output encoding/escaping. Using this encoder comparison table, you will see how ESAPI exceeds other framework encoders and native encoders. |
− | + | The OWASP Encoder Comparison Reference Project is a web-based table reference for how ESAPI and other framework and native language encoding methods work against ASCII characters. | |
− | |||
− | + | == Project Leader == | |
− | |||
− | |||
− | |||
− | |||
− | == | ||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
+ | [[User:Stephanie_Tan|Stephanie Tan]] | ||
==Licensing== | ==Licensing== | ||
OWASP Encoder Comparison Reference is free to use. It is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one. | OWASP Encoder Comparison Reference is free to use. It is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one. | ||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
{| width="200" cellpadding="2" | {| width="200" cellpadding="2" | ||
Line 92: | Line 28: | ||
|} | |} | ||
− | | | + | | valign="top" style="padding-left:25px;width:50px;border-right: 1px dotted gray;padding-right:25px;" | |
+ | |||
+ | [[File:Encoder-reference-table.png|250px|center|link=http://boldersecurity.github.io/encoder-comparison-reference/|alt=Encoder Comparison Reference Table Website Screenshot]] | ||
+ | == Quick Download == | ||
+ | |||
+ | * ESAPI vs Others Encoding Comparison Table: http://boldersecurity.github.io/encoder-comparison-reference/ | ||
+ | * Source Code on Github: https://github.com/boldersecurity/encoder-comparison-reference | ||
+ | |||
+ | == News and Events == | ||
+ | * February 11, 2014: Version 1.0 of the OWASP Encoder Comparison Reference Released | ||
+ | * February 4 2014: OWASP Project accepted! | ||
+ | |||
+ | |||
+ | == Related Projects == | ||
+ | |||
+ | * [[ESAPI]] | ||
+ | * [[XSS_(Cross_Site_Scripting)_Prevention_Cheat_Sheet]] | ||
+ | * [[XSS_Filter_Evasion_Cheat_Sheet]] | ||
+ | |||
− | |||
− | |||
− | |||
− | + | |} | |
− | |||
− | = | + | = Get Involved = |
− | + | Try Version 1.0 Out: | |
− | + | * ESAPI vs Others Encoding Comparison Table: http://boldersecurity.github.io/encoder-comparison-reference/ | |
− | + | Fork the Code! Create a Pull Request! Open Issues and Enhancement Requests! | |
− | * | + | * Source Code on Github: https://github.com/boldersecurity/encoder-comparison-reference |
− | == | + | = What I did with this tool = |
− | + | * "At Blackboard, we used it to further train Developers on how each encoding method differs from others. We used it to explain to Architects why the native framework encoding libraries were inadequate" ~[[User:Stephanie_Tan|Stephanie Tan]] | |
− | * | ||
− | = Road Map | + | = Road Map = |
As of XXX, the priorities are: | As of XXX, the priorities are: | ||
* xxx | * xxx |
Latest revision as of 20:05, 12 February 2016
OWASP Encoder Comparison Reference Project
Libraries and frameworks encode ASCII characters differently. The OWASP Enterprise Security API (ESAPI) is the reference implementation for the most comprehensive and secure output encoding/escaping. Using this encoder comparison table, you will see how ESAPI exceeds other framework encoders and native encoders.
The OWASP Encoder Comparison Reference Project is a web-based table reference for how ESAPI and other framework and native language encoding methods work against ASCII characters.
Project Leader
Licensing
OWASP Encoder Comparison Reference is free to use. It is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.
| valign="top" style="padding-left:25px;width:50px;border-right: 1px dotted gray;padding-right:25px;" |
Quick Download
- ESAPI vs Others Encoding Comparison Table: http://boldersecurity.github.io/encoder-comparison-reference/
- Source Code on Github: https://github.com/boldersecurity/encoder-comparison-reference
News and Events
- February 11, 2014: Version 1.0 of the OWASP Encoder Comparison Reference Released
- February 4 2014: OWASP Project accepted!
Related Projects
|}
Try Version 1.0 Out:
- ESAPI vs Others Encoding Comparison Table: http://boldersecurity.github.io/encoder-comparison-reference/
Fork the Code! Create a Pull Request! Open Issues and Enhancement Requests!
- Source Code on Github: https://github.com/boldersecurity/encoder-comparison-reference
- "At Blackboard, we used it to further train Developers on how each encoding method differs from others. We used it to explain to Architects why the native framework encoding libraries were inadequate" ~Stephanie Tan
As of XXX, the priorities are:
- xxx
- xxx
- xxx
Involvement in the development and promotion of XXX is actively encouraged! You do not have to be a security expert in order to contribute. Some of the ways you can help:
- xxx
- xxx
PROJECT INFO What does this OWASP project offer you? |
RELEASE(S) INFO What releases are available for this project? | |||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|