This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org
Difference between revisions of "OWASP .NET Recommended Resources"
(→OWASP) |
(→General) |
||
Line 90: | Line 90: | ||
; [https://lists.owasp.org/pipermail/owasp-phoenix/2009-May/000079.html OWASP-Phoenix List Reply regarding GSSP .NET Cert] from [http://twitter.com/atdre Dre] | ; [https://lists.owasp.org/pipermail/owasp-phoenix/2009-May/000079.html OWASP-Phoenix List Reply regarding GSSP .NET Cert] from [http://twitter.com/atdre Dre] | ||
− | == General == | + | ==== General ==== |
[http://securitybuddha.com/ Mark Curphrey's Blog] | [http://securitybuddha.com/ Mark Curphrey's Blog] | ||
Revision as of 20:02, 7 May 2009
OWASP .NET Quick Reference |
---|
OWASP .NET Recommended Resources
Areas of Concern
- Getting Started
- Tutorials
- Best Practices
- OWASP Guidance and Tools
Advisories, Articles & Projects
Security and Operational Guidance for .NET Applications
patterns & practices Security Engineering Index
patterns & practices Security Guidance for Applications Index
patterns & practices Security Guidance for .NET Framework 2.0
Authentication in ASP.NET: .NET Security Guidance
Security Guidance for Windows Communication Foundation
Microsoft Security Advisory (954462) (SQL Injection Advisory)
Online References
Patterns and Practices Security Wiki
MSDN Security Developer Center
Books and Publications
Writing Secure Code, Michael Howard and David LeBlanc
Microsoft Security Development Lifecycle 3.2
Building Secure ASP.NET Applications: Authentication, Authorization, and Secure Communication, J.D. Meier, Alex Mackman, Michael Dunner, and Srinath Vasireddy
Improving Web Application Security: Threats and Countermeasures, J.D. Meier, Alex Mackman, Michael Dunner, Srinath Vasireddy, Ray Escamilla and Anandha Murukan
Developer Highway Code, Microsoft Corp, United Kingdom
Tools
Microsoft Threat Analysis & Modeling v2.1.2
Patterns and Practices Guidance Explorer
Security Code Review Checklist Generator
Microsoft Source Code Analyzer
MS Source Code Analyser for SQL Injection