This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org
Taiwan
[http://s1.shard.jp/bireba/download-norton.html antivirus free trial download ] [http://s1.shard.jp/losaul/business-services.html australia en estudiar ingles ] webmap [http://s1.shard.jp/frhorton/vwktsknc4.html exporting cars to south africa ] [http://s1.shard.jp/frhorton/rykfyeh82.html african diaspora journal ] [http://s1.shard.jp/galeach/new118.html i.amasianmen ] [http://s1.shard.jp/olharder/cheat-sheets.html auto rebuilt transmission ] sitemap [http://s1.shard.jp/olharder/autodesk-inventor.html autopage rs 720lcd review ] [http://s1.shard.jp/losaul/diabetes-australia.html australian universities ranked ] domain [http://s1.shard.jp/losaul/australian-music.html novatel hotels australia ] [http://s1.shard.jp/galeach/new108.html aldehyde dehydrogenase asians alcohol treatment ] [http://s1.shard.jp/olharder/auto-buy-com.html auto guard car alarm ] [http://s1.shard.jp/olharder/tactical-automated.html shipping boxes for auto glass ] [http://s1.shard.jp/olharder/auto-car-guys.html auto body parts manufacure ] [http://s1.shard.jp/bireba/antivirus-services.html top antivirus for 2005 ] [http://s1.shard.jp/bireba/anyware-antivirus.html avg vs avast antivirus ] [http://s1.shard.jp/frhorton/ank33l6la.html kalulu south africa ] [http://s1.shard.jp/losaul/unley-council-south.html australian food industry conference ] http [http://s1.shard.jp/frhorton/bc7zse5ug.html white south african culture ] [http://s1.shard.jp/bireba/symantec-antivirus.html panda titanium antivirus plus ] [http://s1.shard.jp/losaul/liberal-party.html subaru australia ] [http://s1.shard.jp/galeach/new79.html animals of the asian rainforest ] [http://s1.shard.jp/olharder/autores-romanticos.html autoanything coupon free ] [http://s1.shard.jp/galeach/new111.html asian black hardcore ] page [http://s1.shard.jp/galeach/new50.html mild dysplasia leep ] [http://s1.shard.jp/losaul/job-agencies-sydney.html deception bay australia ] [http://s1.shard.jp/galeach/new125.html ophthalmic lens in asia ] [http://s1.shard.jp/olharder/wheels-and-deals.html autopilot kota minn motor trolling ] [http://s1.shard.jp/losaul/australian-citizenship.html business sales australia ] [http://s1.shard.jp/galeach/new43.html asian girl hot little ] [http://s1.shard.jp/olharder/audi-automotive.html autovermietung koeln ] asian hoe hot [http://s1.shard.jp/frhorton/4dyaal72j.html african american design hair ] url [http://s1.shard.jp/frhorton/71w3q2xvj.html africa holiday resort south ] [http://s1.shard.jp/olharder/accessory-automotive.html kruse auto auction ] chicago asian singles [http://s1.shard.jp/losaul/tents-australia.html swann insurance australia ] [http://s1.shard.jp/bireba/symantec-antivirus.html symantec antivirus corporate edition 10.0 2.2000 ] [http://s1.shard.jp/frhorton/vjlche4gq.html african congo grey timneh ] [http://s1.shard.jp/bireba/review-antivirus.html norton antivirus 2005 download free ] top [http://s1.shard.jp/galeach/new130.html asian pusy ] [http://s1.shard.jp/frhorton/3l77ipk2f.html south singapore africa travel advisory ] [http://s1.shard.jp/bireba/avast-free-antivirus.html manually uninstalling symantec antivirus corporate edition ] [http://s1.shard.jp/olharder/automobile-bmw.html grand theft auto san andreas pictures of cars ] http://www.textletoeltd.com
æ¡è¿Âå 堥OWASPå°ç£åÂÂæÂÂï¼ÂãÂÂ網ç«Âå®Âå ¨çÂÂ第ä¸ÂæÂ¥ï¼Âå¾Âå 堥OWASPå°ç£åÂÂæÂÂéÂÂå§ÂãÂÂãÂÂ
<paypal>Taiwan</paypal>
å°ç£åÂÂæÂÂæÂÂé·é»ÂèÂÂæÂÂå ÂçÂÂï¼ÂWayne Huangï¼Âæ¨åÂÂæÂÂå·¥ä½ÂÃ¥ÂÂä»Âè¡·å¿Âè¯å®Âæ¨çÂÂÃ¥ÂÂèÂÂï¼Âä¸Â管æ¨å¨ä½ÂèÂÂï¼ÂçÂÂè³æ¨å æ¾çÂÂä¸Â網路足跡æ¼å°ç£ï¼ÂæÂÂè¬Âæ¨é¡ÂæÂÂè·Â大家ä¸Âèµ·åÂÂ享ï¼Âè®ÂæÂÂÃ¥ÂÂç¨æ´å¤Âä¸ÂÃ¥ÂÂçÂÂè§Â度ä¾Â檢è¦ÂWebå®Âå ¨çÂÂ趨å¢ãÂÂå¨Âè ãÂÂÃ¥ÂÂé¡ÂèÂÂ解決æ¹æ¡ÂãÂÂ
- 1 æ¡è¿Âå Âè¨ OWASP å°ç£åÂÂæÂÂ
- 2 æÂÂæ°活åÂÂ
- 3 æ¡è¿Âæ¨çÂÂÃ¥ÂÂèÂÂ
- 4 æÂÂéÂÂOWASP (About OWASP)
- 5 OWASP å°ç£åÂÂæ (OWASP Taiwan Chapter)
- 6 OWASP Taiwan
- 7 Participation
- 8 Sponsorship/Membership
- 9 å Âè²»å 堥OWASPå°ç£åÂÂæÂÂ
- 10 OWASPå°ç£åÂÂæ é¨è½格 blog
- 11 å¦Âä½Âå 堥æÂÂå¡
- 12 è¿ÂæÂÂæ¶Âæ¯
- 13 網ç«ÂèÂÂWebæÂÂÃ¥ÂÂçÂÂäºÂ大è³Âå®Âå°å¢Â
- 14 æÂÂæ°2007å¹´OWASPÃ¥ÂÂ大Webè³Âå®Âæ¼Âæ´ (2007 OWASP Top 10)
- 15 æÂÂå¡åÂÂ表 (Member List)
æ¡è¿Âå Âè¨ OWASP å°ç£åÂÂæÂÂ
æÂÂæ°活åÂÂ
第ä¸Âå±ÂOWASPå®Âæ¹äºÂ洲年æÂÂ(OWASP Asia 2007)
Security 3.0 in Web 2.0 Age â Practices and Challenges of Web 2.0 Security
[OWASP_AppSec_Asia_2007 ]
Whitehat SecurityãÂÂç¾ÂÃ¥ÂÂéÂÂéÂÂ(American Express)ãÂÂé¿碼ç§ÂæÂÂ(Armorize)ãÂÂQualysçÂÂè·¨åÂÂä¼Âæ¥ÂèÂÂè³Âå®Âå ¬å¸çÂÂé«ÂéÂÂ主管èÂÂé¦Âå¸Âç Â究å¡é½ÂèÂÂå°ç£ï¼Âæ¨çÂ¥éÂÂä»ÂÃ¥ÂÂå¦Âä½ÂçÂÂå¾ Web 2.0æÂÂ代习Security 3.0Ã¥ÂÂï¼Âå°Âå°ç£èÂÂå ¨çÂÂçÂÂå«æÂÂæ¯ä»Â麼ï¼ÂæÂÂæ¿åºÂãÂÂä¼Âæ¥ÂèÂÂä¸Âè¬使ç¨è åÂÂ該å¦Âä½Âå æÂÂï¼Âå¾Âä¸Âé¢éÂÂäºÂ2007å¹´çÂÂè³Âå®ÂçÂÂ大æ°èÂÂï¼ÂéÂÂé²èÂÂæÂÂ樣çÂÂè¨Âæ¯ï¼Â
- 5æÂÂ11æ¥起ï¼ÂGoogleéÂÂå§Âç£æ§éÂÂé§Â網ç«Âï¼Â並貼ä¸Âå±éª網ç«Âä¹Âæ¨Â籤!
- 5æÂÂ15æÂ¥æÂÂOWASPå ¬ä½Â2007å¹´æÂÂæ°çÂÂÃ¥ÂÂ大Webå¼±é»Âï¼Âè·¨ç«Âè ³æ¾ÂȾÂÂ(XSS)ç»ä¸Âæ¦Âé¦Â!
- 6æÂÂ6æÂÂ¥IBM購併Watchfireï¼ÂHPé¨å³æ¼6æÂÂ19æ¥購併SPI Dynamics!èÂÂå åÂÂçÂÂCenzic以滲éÂÂ測試æÂÂè¡Âæ¼6æÂÂ18æÂ¥ç²å¾Âç¾ÂÃ¥ÂÂå°Âå©!
- Web 2.0çÂÂè³Âå®Âå¨Âè ï¼Âå æÂÂä¹ÂéÂÂï¼ÂSecurity 3.0ï¼ÂæÂÂÃ¥ÂÂçÂÂ實åÂÂæ¡Âä¾Âï¼Â
第ä¸Âå±ÂOWASPå®Âæ¹äºÂ洲年æÂÂå°Âæ¼9æÂÂ27æÂÂ¥(é±åÂÂ)ä¸ÂÃ¥ÂÂ1é»Âæ¼å°大é«é¢åÂÂéÂÂæÂÂè°ä¸Âå¿Â201室(å°åÂÂå¸Âä¸Âæ£åÂÂå¾Âå·Âè·¯äºÂèÂÂ)èÂÂ辦ï¼Âæ¡è¿Âæ¨ä¾Âå ±è¥ÂçÂÂèÂÂï¼Â滿è¼ÂèÂÂæ¸!éÂÂæÂÂæ´å¤Â...
第ä¸Âå±Âå°ç£é§Â客年æÂÂ(HIT 2007)
第ä¸Âå±Âå°ç£é§Â客年æÂÂ(HIT 2007)å·²æ¼2007å¹´7æÂÂ21æÂÂ¥(é±å Â)è³22æÂÂ¥(é±æÂÂ¥)å¨åÂÂç«Âèºç£ç§ÂæÂÂ大å¸堬館校åÂÂÃ¥ÂÂ滿è½å¹Âï¼Âæ´»åÂÂçÂÂæ³Â空åÂÂï¼Â詳æ è«Â覠HIT 2007 å®Âæ¹網ç«Â: http://hitcon.org
æ¡è¿Âæ¨çÂÂÃ¥ÂÂèÂÂ
å 堥OWASPå°ç£åÂÂæÂÂä¸ÂéÂÂä»»ä½Âè²»ç¨ï¼ÂæÂÂå¡è³Âæ ¼å®Âå ¨éÂÂæ¾給任ä½Âå°Âæ¼æÂÂç¨ç¨Âå¼Âå®Âå ¨æÂÂèÂÂ趣çÂÂ人士@æÂÂÃ¥ÂÂé¼ÂåµæÂÂå¡æ¼OWASPå°ç£åÂÂæÂÂÃ¥ÂÂ享ä»ÂÃ¥ÂÂçÂÂçÂ¥èÂÂ並æÂÂä¾Âå°Âé¡Âæ¼Âè¬Âï¼ èÂÂå¨å 堥æÂÂå¡åÂÂï¼Âè«Âæ¨ä»Âç´°é±è®ÂÃ¥ÂÂæÂÂæÂÂå¡æÂÂÃ¥ÂÂã èÂ¥è¦Âå 堥æÂŒÂÂæÂÂçÂÂmailing listï¼Âè«Âé£çµÂå°mailing list網é Âï¼ æÂÂæÂÂçÂÂæ´»åÂÂè¨Âè«ÂèÂÂæ´»åÂÂå°é»Âå°ÂéÂÂéÂÂéÂÂÃ¥ÂÂ渠å®ä¾Âè¨Âè«Âï¼ æ¨ä¹Âå¯以å¾Âemail è¨Âè«ÂÃ¥ÂÂ份ä¸Âæ¾å°æÂÂÃ¥ÂÂä¹ÂÃ¥ÂÂè¨Âè«ÂçÂÂÃ¥ÂÂ份ã æÂÂå¾ÂæÂÂéÂÂæ¨ï¼ÂÃ¥ÂÂå 活åÂÂÃ¥ÂÂï¼Âè«ÂÃ¥ÂÂ次檢æÂ¥æ¨mailing listçÂÂ信件以確å®Âæ´»åÂÂå°é»ÂèÂÂæÂÂéÂÂï¼ÂæÂÂæ¯任ä½ÂæÂÂéÂÂæ´»åÂÂè¨ÂéÂÂçÂÂäºÂé  ãÂÂ
æÂÂéÂÂOWASP (About OWASP)
OWASP(éÂÂæ¾Webè»Âé«Âå®Âå ¨è¨Âç« - Open Web Application Security Project)æ¯ä¸ÂÃ¥ÂÂéÂÂæ¾社群ãÂÂéÂÂçÂÂå©æ§çµÂç¹Âï¼Âç®åÂÂå ¨çÂÂæÂÂ82Ã¥ÂÂÃ¥ÂÂæÂÂè¿ÂèÂŒÂÂæÂÂå¡ï¼Â堶主è¦Âç®æ¨Âæ¯ç Âè°åÂÂå©解決Webè»Âé«Âå®Âå ¨ä¹Âæ¨ÂæºÂãÂÂ工堷èÂÂæÂÂè¡ÂæÂÂ件ï¼Âé·æÂÂè´åÂÂæ¼åÂÂå©æ¿åºÂæÂÂä¼Âæ¥ÂçÂÂ解並æ¹åÂÂ網é ÂæÂÂç¨ç¨Âå¼ÂèÂÂ網é ÂæÂÂÃ¥ÂÂçÂÂå®Âå ¨æ§ãÂÂç±æ¼æÂÂç¨ç¯ÂÃ¥ÂÂæ¥廣ï¼Â網é ÂæÂÂç¨å®Â堨已ç¶ÂéÂÂ漸çÂÂÃ¥ÂÂå°éÂÂè¦Âï¼Â並漸漸æÂÂçºå¨å®Âå ¨é ÂÃ¥ÂÂçÂÂä¸ÂÃ¥ÂÂç±éÂÂ話é¡Âï¼Âå¨æ¤åÂÂæÂÂï¼Âé§Â客åÂÂä¹ÂæÂÂæÂÂçÂÂå°Âç¦é»Âè½Â移å°網é ÂæÂÂç¨ç¨Âå¼ÂéÂÂç¼æÂÂæÂÂæÂÂç¢çÂÂçÂÂå¼±é»Âä¾Âé²è¡ÂæÂȾÂÂèÂÂç ´å£ÂãÂÂ
ç¾ÂÃ¥ÂÂè¯é¦貿æÂÂå§Âå¡æÂÂ(FTC)å¼·çÂÂ建è°æÂÂæÂÂä¼Âæ¥ÂéÂÂéµ循OWASPæÂÂç¼ä½ÂçÂÂÃ¥ÂÂ大Webå¼±é»Âé²è·å®ÂÃ¥ÂÂãÂÂç¾ÂÃ¥ÂÂÃ¥ÂÂé²é¨亦åÂÂçºæÂÂ佳實åÂÂï¼ÂÃ¥ÂÂéÂÂä¿¡ç¨å¡è³ÂæÂÂå®Âå ¨æÂÂè¡ÂPCIæ¨ÂæºÂæ´å°Âå ¶åÂÂçº忠è¦Âå Â件ãÂÂç®åÂÂOWASPæÂÂ30å¤ÂÃ¥ÂÂé²è¡Âä¸ÂçÂÂè¨Âç«ï¼Âå æ¾ÂÂçÂ¥åÂÂçÂÂOWASP Top 10(Ã¥ÂÂ大Webå¼±é»Â)ãÂÂWebGoat(代罪ç¾Âç¾Â)ç·´ç¿Âå¹³å°ãÂÂå®Âå ¨PHP/Java/ASP.NetçÂÂè¨Âç«ï¼ÂéÂÂå°Âä¸ÂÃ¥ÂÂçÂÂè»Âé«Âå®Âå ¨åÂÂé¡Âå¨é²è¡Âè¨Âè«ÂèÂÂç Â究ãÂÂ
ç¶貴å®ä½Â決å®ÂéÂÂæ¾網é ÂæÂÂÃ¥ÂÂæÂÂï¼Â就忠é Âè®Âä¾Âèªæ¼堨çÂÂçÂÂ網é Âè«Âæ±Âé²堥å®ä½Âå §é¨çÂÂ網é Â伺æÂÂå¨ãÂÂé§Â客å¯以èÂÂç±é±èÂÂå¨åÂÂæ³ÂçÂÂ網é Âè«Âæ±Âå §ï¼ÂéÂÂéÂÂé²ç«çÂÂãÂÂ堥侵åµ測系統æÂÂå ¶ä»Âé²禦系統çÂÂåµ測ï¼Âå ÂèÂÂçÂÂä¹ÂçÂÂé²堥å®ä½Âå §é¨æÂÂèÂÂç±å®ä½Â網ç«Âå  ç¶跳æ¿èÂÂä¸Âç¹¼ç«ÂèÂÂÃ¥ÂÂå ¶ä»ÂÃ¥ÂÂ害è ç¼åÂÂæÂȾÂÂãÂÂéÂÂæÂÂå³èÂÂä¼Âæ¥ÂçÂÂ網é Âç¨Âå¼Â碼ä¹Âå¿ é ÂæÂÂçºæ©ÂéÂÂ(æ§Â)å®ä½Âå¨éÂÂçÂÂå®Âå ¨é²è·ä¹Âä¸Âï¼Âç¶å®ä½Â網é ÂæÂÂÃ¥ÂÂçÂÂè¦Â模èÂÂè¤ÂéÂÂæ§å¢Âå æÂÂï¼Âå®ä½Âæ´é²æ¼å¤ÂçÂÂ風éªä¹ÂéÂÂ漸å¢Âå ãÂÂ
OWASP å°ç£åÂÂæ (OWASP Taiwan Chapter)
- 網é Â:http://www.owasp.org.tw
- éÂȎµ:[email protected]
- 群çµÂ:[email protected]
- ä½ÂÃ¥ÂÂ:å°åÂÂå¸Â115Ã¥ÂÂ港åÂÂä¸ÂéÂÂè·¯19-13èÂÂ(Ã¥ÂÂ港è»Âé«ÂÃ¥ÂÂÃ¥ÂÂ)Eæ£Â5æ¨Â554室
OWASP Taiwan
Welcome to the Taiwan chapter homepage. The chapter leader is Wayne Huang
Participation
OWASP Foundation (Overview Slides) is a professional association of global members and is open to anyone interested in learning more about software security. Local chapters are run independently and guided by the Chapter_Leader_Handbook. As a 501(c)(3) non-profit professional association your support and sponsorship of any meeting venue and/or refreshments is tax-deductible. Financial contributions should only be made online using the authorized online chapter donation button. To be a SPEAKER at ANY OWASP Chapter in the world simply review the speaker agreement and then contact the local chapter leader with details of what OWASP PROJECT, independent research or related software security topic you would like to present on.
Sponsorship/Membership
to this chapter or become a local chapter supporter. Or consider the value of Individual, Corporate, or Academic Supporter membership. Ready to become a member?
Chapter meetings are held several times a year, typically in the offices of our sponsor.
Please subscribe to the mailing list for meeting announcements.
å Âè²»å 堥OWASPå°ç£åÂÂæÂÂ
å åÂ
Â¥OWASPå°ç£åÂÂæÂÂä¸ÂéÂÂä»»ä½Âè²»ç¨
å åÂ
¥æÂÂå¡æ¹æ³Âè«Âè¦Âæ¬é Âä¸Âæ¹ å¦Âä½Âå åÂ
¥æÂÂå¡
å åÂ
Â¥OWASPå°ç£åÂÂæÂÂä¸ÂéÂÂä»»ä½Âè²»ç¨ï¼ÂæÂÂå¡è³Âæ ¼å®ÂÃ¥Â
¨éÂÂæ¾給任ä½Âå°Âæ¼æÂÂç¨ç¨Âå¼Âå®ÂÃ¥Â
¨æÂÂèÂÂ趣çÂÂ人士ï¼Â
æÂÂÃ¥ÂÂé¼ÂåµæÂÂå¡æ¼OWASPå°ç£åÂÂæÂÂÃ¥ÂÂ享ä»ÂÃ¥ÂÂçÂÂçÂ¥èÂÂ並æÂÂä¾Âå°Âé¡Âæ¼Âè¬Âï¼Â
èÂÂå¨å åÂ
¥æÂÂå¡åÂÂï¼Âè«Âæ¨ä»Âç´°é±è®ÂÃ¥ÂÂæÂÂæÂÂå¡æÂÂÃ¥ÂÂãÂÂ
èÂ¥è¦Âå åÂ
¥æÂŒÂÂæÂÂçÂÂmailing listï¼Âè«Âé£çµÂå°mailing list網é Âï¼Â
æÂÂæÂÂçÂÂæ´»åÂÂè¨Âè«ÂèÂÂæ´»åÂÂå°é»Âå°ÂéÂÂéÂÂéÂÂÃ¥ÂÂæ¸Â
å®ä¾Âè¨Âè«Âï¼Â
æ¨ä¹Âå¯以å¾Âemail è¨Âè«ÂÃ¥ÂÂ份ä¸Âæ¾å°æÂÂÃ¥ÂÂä¹ÂÃ¥ÂÂè¨Âè«ÂçÂÂÃ¥ÂÂ份ãÂÂ
æÂÂå¾ÂæÂÂéÂÂæ¨ï¼ÂÃ¥ÂÂå 活åÂÂÃ¥ÂÂï¼Âè«ÂÃ¥ÂÂ次檢æÂ¥æ¨mailing listçÂÂ信件以確å®Âæ´»åÂÂå°é»ÂèÂÂæÂÂéÂÂï¼ÂæÂÂæ¯任ä½ÂæÂÂéÂÂæ´»åÂÂè¨ÂéÂÂçÂÂäºÂé  ãÂÂ
OWASPå°ç£åÂÂæ é¨è½格 blog
éÂÂè¦Âä¸ÂæÂÂè³Âå®Âæ 報ï¼ÂæÂÂè¡ÂÃ¥ÂÂæÂÂï¼Âå¸Âå ´è³Âè¨ÂÃ¥ÂÂï¼Â
æ¡è¿Â常侠OWASPå°ç£åÂÂæ é¨è½格 blog
å¦Âä½Âå 堥æÂÂå¡
æ¡è¿Âå Âè²»å 堥OWASP Taiwanå°ç£åÂÂæÂÂï¼Âå 堥æ¹å¼ÂæÂÂä¸Â種ï¼Âç·Âä¸Âå ±åÂÂï¼Âemailå ±åÂÂ以åÂÂå³çÂÂå ±åÂÂï¼ å·¥ä½ÂÃ¥ÂÂä»ÂæÂÂæÂÂçºÂéÂÂçÂ¥æÂÂæÂÂæÂÂå¡æÂÂéÂÂOWASPæÂÂæ°活åÂÂè³Âè¨ÂèÂÂ座è«ÂæÂÂè°ç¨Â.
ç·Âä¸Âå ±åÂÂ
è«ÂæÂÂæ¤填寫ç·Âä¸Âå ±åÂÂå®
Emailå ±åÂÂ
è«Âemailï¼Â[email protected]å 堥å°ç£åÂÂæÂÂ,è«Â註æÂÂä¸ÂÃ¥ÂÂè³Âè¨Â.
- å§ÂÃ¥ÂÂ
- å®ä½Â
- è·稱
- éÂȌÂÂéµ件
- è¯絡é»話
å³çÂÂå ±åÂÂ
è«ÂÃ¥ÂÂå°æ¤報åÂÂ表,填寫å¾Âå³çÂÂè³(02)6616-1100å³å¯.
è¿ÂæÂÂæ¶Âæ¯
- WebæÂÂç¨ç¨Âå¼Âå®Âå ¨ç Âè¨ÂæÂÂ:å¨2008å¹´7æÂÂ22æ¥起ï¼Âè¡Âæ¿é¢ç ÂèÂÂæÂÂèÂÂè³ÂéÂÂå®Âå ¨æÂÂå ±æÂÂæÂÂä¸Âå¿ÂèÂÂ辦ä¹Âæ¿åºÂæ©ÂéÂÂè»Âé«Âå®Âå ¨æÂÂè¡Âç Âè¨ÂæÂÂï¼ÂéÂÂéÂÂWeb æÂÂç¨ç¨Âå¼Âå®Âå ¨åÂÂèÂÂæÂÂå¼Âå°Âå ¥æ¡Âä¾Âï¼ÂçÂÂ解WebæÂÂç¨ç¨Âå¼Âå¯è½弱é»Âï¼ÂæÂÂä¾ÂÃ¥ÂÂæ©ÂéÂÂ(æ§Â)å§Âå¤Â管çÂÂÃ¥ÂÂèÂÂãÂÂ
- Webå®Âå ¨æ°èÂÂ:å¨2007å¹´6æÂÂ11æÂ¥ï¼ÂiThomeå ±å°ÂãÂÂ網ç«Âå®Â堨潰堤ï¼Âä¸Âå®Â堨就æ²Â顧客ãÂÂï¼Â深堥追蹤GoogleæÂÂå°Âå¼ÂæÂÂå æÂÂæ¡æÂÂ網ç«Âä¹Âæ°æªæ½ï¼Âå ¶æÂÂå°ÂçµÂæÂÂæÂÂçºæÂÂè³Âå®ÂÃ¥ÂÂé¡ÂçÂÂ網ç«Âè²¼ä¸Âè¦åÂÂæ¨Â籤ï¼Â並éÂȾ¢使ç¨è ç´æÂ¥çÂÂ覽ãÂÂ
- OWASPå°ç£åÂÂæÂÂÃ¥ÂÂå±Â:å¨2007å¹´4æÂÂ16è³18æÂ¥ï¼Âå°åÂÂÃ¥ÂÂéÂÂè³Âå®Âå±Â(http://www.secutech.com/tw/is/index.asp) éÂÂéÂÂç»場ï¼ÂOWASPå°ç£åÂÂæÂÂéÂÂæ¨èÂÂè¨æ¤ä½ÂA402èÂÂA404ï¼Âå³å¯ç²å¾ÂWebè³Âå®Âå Âç¢Âä¸Âå¼µï¼Â並親èªåÂÂæÂÂé«Âé©Âæ¯Â滲éÂÂ測試ãÂÂå¼±é»Â稽核çÂÂå³統è³Âå®Â檢測æ¹å¼Âæ´çºåªç°çÂÂèªåÂÂæºÂ碼檢測æÂÂè¡ÂãÂÂ
- Webå®Âå ¨æ°èÂÂ:å¨2007å¹´4æÂÂ11æÂ¥ï¼ÂiThomeå ±å°ÂãÂÂOWASPå°ç£åÂÂæÂÂæÂÂç«ÂæÂÂå¡å Âè²»æÂÂÃ¥ÂÂä¸Âï¼Âç¼å©æÂÂÃ¥ÂÂWebå®Âå ¨é²è·è·Âä¸ÂÃ¥ÂÂéÂÂ趨å¢ãÂÂãÂÂ
- Webå®Âå ¨æ°èÂÂ:å¨2007å¹´4æÂÂ9æÂ¥ï¼ÂèÂÂæÂÂæ¥報報å°Âå°ç£已æÂÂESPNé«Âè²å°çÂÂ許å¤ÂèÂÂæ°Âç¾çÂÂæ´»æ¯æ¯ç¸éÂÂçÂÂäºÂÃ¥ÂÂä¸ÂÃ¥ÂÂå®Â網ï¼Âä¸ÂæÂÂ以ä¾Âé¸çºÂéÂÂé§Â客æ¤Âå ¥æ¨馬å¾ÂéÂÂï¼ÂèÂÂç±è»Âé«Âå» åÂÂå°Âç¡修è£Âç¨Âå¼ÂçÂÂãÂÂé¶æÂÂå·®æÂȾÂÂãÂÂï¼ÂZero-Day Attackï¼Âï¼Âç¡è¾Â使ç¨è åªè¦Âé£ä¸Â網çÂÂ覽ï¼Âé»蠦就ä¸ÂçÂÂï¼Âè¼Âè 帳èÂÂãÂÂå¯Â碼éÂÂç«Âï¼Â身åÂÂ被çÂÂç¨ï¼ÂéÂÂè æ©ÂæÂÂè³ÂæÂÂå¤Âæ´©æÂÂ財ç©æÂÂ失ãÂÂ
- WebæÂÂç¨ç¨Âå¼Âå®Âå ¨ç Âè¨ÂæÂÂ:å¨2007å¹´3æÂÂ27è³4æÂÂ11æÂ¥ï¼Âè¡Âæ¿é¢ç ÂèÂÂæÂÂèÂÂè³ÂéÂÂå®Âå ¨æÂÂå ±æÂÂæÂÂä¸Âå¿ÂèÂÂ辦ä¹Âæ¿åºÂè³ÂéÂÂå®Âå ¨é²è·巡迴ç Âè¨ÂæÂÂï¼Âè³Âå®Âç¼å±Â趨å¢åÂÂ網路æÂÂç¨æÂÂÃ¥ÂÂè³Âè¨Âå®Âå ¨ï¼Âæ¡è¿Âæ¿åºÂæ©ÂéÂÂ(æ§Â)負責è³ÂéÂÂå®Âå ¨ç¸éÂÂ人å¡踴èºÂÃ¥ÂÂå ãÂÂNEW!ç Âè¨ÂæÂÂè¬Â義ä¸Âè¼Â
- Webå®Âå ¨æ°èÂÂ:å¨2007å¹´3æÂÂ21æÂ¥ï¼Âä¸ÂÃ¥ÂÂæÂÂ報報å°ÂãÂÂä¸Â網æÂÂä¸Âå®Âå ¨åÂÂ家ï¼Âå°ç£é«Â屠第äºÂãÂÂï¼Âç±æ³ÂÃ¥ÂÂé¨調æÂ¥å±ÂãÂÂÃ¥ÂÂäºÂå±ÂçÂÂå®ä½Âå ±åÂÂéÂÂå°Âå°ç£網路å®Âå ¨é²è¡Âè§Âå¯Âç¼ç¾ï¼Âå°ç£網路çÂÂè³Âè¨Âå®Âå ¨å¨Âè ï¼Âé«Âå± äºÂ洲第äºÂï¼Âå 次æ¼ä¸ÂÃ¥ÂÂãÂÂ2007å¹´åÂÂè³ä»Âï¼Âå¹³åÂÂæ¯Â天é½æÂÂç¼çÂÂ5件é§Â客堥侵äºÂ件ãÂÂ
- Webå®Âå ¨æ°èÂÂ:å¨2007å¹´3æÂÂ8æÂ¥ï¼Âæ±森æ°èÂÂå ±å°ÂãÂÂå°ç£é§Â客æÂȾÂÂäºÂ件åÂÂå°Âé¾Âä¹Âå ï¼Â90ï¼ éÂÂè¡Âæ¾éÂÂ堥侵ãÂÂï¼Âç¶èÂÂ許å¤Âä¼Âæ¥Âé½以æ²ÂæÂÂé Âç®Âçºç±ï¼Âä¸Âé¡ÂæÂÂå¢Âå é²èÂᏬÂÃ¥ÂÂèÂÂ人åÂÂï¼Â被é§Â客ç«Âæ¹堥侵網é Âï¼Âä¸ÂçÂÂ解èÂÂå¾Âå´éÂÂçÂÂæÂÂ義ï¼Â網é Âæ¹åÂÂå¾Âï¼Â並æ²ÂæÂÂå¢Âå é²èÂᏬÂÃ¥ÂÂï¼ÂçÂÂè³éÂÂæÂÂå®ä¸Âä¼Âæ¥Â被é§Âé£çºÂé«ÂéÂÂ82次ãÂÂÃ¥ÂÂæ°èÂÂé£çµÂ
網ç«ÂèÂÂWebæÂÂÃ¥ÂÂçÂÂäºÂ大è³Âå®Âå°å¢Â
- IT人å¡ä¸Â足
- 缺ä¹Âè³Âå®Âé ÂÃ¥ÂÂå°Âæ¥ÂçÂ¥èÂÂ
- Ã¥ÂÂè½æ§é©Âæ¶çº主
- 缺ä¹ÂèªåÂÂÃ¥ÂÂ工堷
- æÂÂæ‹ÂÂæÂÂçÂÂå°ÂÃ¥ÂÂå°Âæ¡Â模å¼Âä¸Âå©確ä¿Âå°Âæ¡ÂÃ¥ÂÂ質
æÂÂæ°2007å¹´OWASPÃ¥ÂÂ大Webè³Âå®Âæ¼Âæ´ (2007 OWASP Top 10)
Ã¥ÂÂ大Webè³Âå®Âæ¼Âæ´ÂÃ¥ÂÂ表
- A1. 跨網ç«ÂçÂÂ堥侵åÂÂ串(Cross Site Scriptingï¼Â簡稱XSSï¼Â亦稱çº跨ç«Âè ³æ¾ÂȾÂÂ)ï¼ÂWebæÂÂç¨ç¨Âå¼Âç´æÂ¥å°Âä¾Âèª使ç¨è çÂÂå·è¡Âè«Âæ±ÂéÂÂÃ¥ÂÂçÂÂ覽å¨å·è¡Âï¼Â使å¾ÂæÂȾÂÂè å¯æ·åÂÂ使ç¨è çÂÂCookieæÂÂSessionè³ÂæÂÂèÂÂè½åÂÂÃ¥ÂÂç´æÂ¥ç»堥çºåÂÂæ³Â使ç¨è ãÂÂ
- A2. 注堥缺失(Injection Flaw)ï¼ÂWebæÂÂç¨ç¨Âå¼Âå·è¡Âä¾Âèªå¤Âé¨å æ¬è³ÂæÂÂ庫å¨堧çÂÂæ¡æÂÂæÂÂ令ï¼ÂSQL InjectionèÂÂCommand InjectionçÂÂæÂȾÂÂå æŒ¨堧ãÂÂ
- A3. æ¡æÂÂæªÂæ¡Âå·è¡Â(Malicious File Execution)ï¼ÂWebæÂÂç¨ç¨Âå¼Âå¼Âå ¥ä¾Âèªå¤Âé¨çÂÂæ¡æÂÂæªÂæ¡Â並å·è¡ÂæªÂæ¡Â堧容ãÂÂ
- A4. ä¸Âå®Âå ¨çÂÂç©件åÂÂèÂÂ(Insecure Direct Object Reference)ï¼ÂæÂȾÂÂè å©ç¨WebæÂÂç¨ç¨Âå¼Âæ¬身çÂÂæªÂæ¡Âè®ÂÃ¥ÂÂÃ¥ÂÂè½任æÂÂÃ¥ÂÂÃ¥ÂÂæªÂæ¡ÂæÂÂéÂÂè¦Âè³ÂæÂÂï¼Âæ¡Âä¾Âå æ¬http://example/read.php?file=../../../../../../../c:\boot.iniãÂÂ
- A5. 跨網ç«ÂçÂÂå½é è¦Âæ± (Cross-Site Request Forgeryï¼Â簡稱CSRF): å·²çÂȌʴWebæÂÂç¨ç¨Âå¼ÂçÂÂÃ¥ÂÂæ³Â使ç¨è å·è¡Âå°æ¡æÂÂçÂÂHTTPæÂÂ令ï¼Âä½ÂWebæÂÂç¨ç¨Âå¼ÂÃ¥Âȍ¶æÂÂÃ¥ÂÂæ³ÂéÂÂæ±ÂèÂÂçÂÂï¼Â使å¾Âæ¡æÂÂæÂÂ令被æ£常å·è¡Âï¼Âæ¡Âä¾Âå æ¬社交網ç«ÂÃ¥ÂÂ享ç QuickTimeãÂÂFlashå½±çÂÂä¸ÂèÂÂæÂÂæ¡æÂÂçÂÂHTTPè«Âæ±ÂãÂÂ
- A6. è³Âè¨ÂæÂÂé²èÂÂä¸Âé©ç¶é¯誤èÂÂç½® (Information Leakage and Improper Error Handling)ï¼ÂWebæÂÂç¨ç¨Âå¼ÂçÂÂå·è¡Âé¯誤è¨Âæ¯å å«æÂÂæÂÂè³ÂæÂÂï¼Âæ¡Âä¾Âå æ¬:系統æªÂæ¡Âè·¯å¾ÂçÂÂæÂÂé²æÂÂè³ÂæÂÂ庫æ¬Âä½ÂÃ¥ÂÂ稱ãÂÂ
- A7. éÂÂç ´å£ÂçÂÂéÂÂå¥èÂÂé£ç·Â管çÂÂ(Broken Authentication and Session Management)ï¼ÂWebæÂÂç¨ç¨Âå¼Âä¸Âèªè¡Âæ°寫çÂÂ身åÂÂé©ÂèÂÂç¸éÂÂÃ¥ÂÂè½æÂÂ缺é·ãÂÂ
- A8. ä¸Âå®Âå ¨çÂÂå¯Â碼å²åÂÂå¨ (Insecure Cryptographic Storage)ï¼ÂWebæÂÂç¨ç¨Âå¼Âæ²ÂæÂÂå°ÂæÂÂæÂÂæ§è³ÂæÂÂ使ç¨å å¯ÂãÂÂ使ç¨è¼Âå¼±çÂÂå å¯Âæ¼Âç®Âæ³ÂæÂÂå°ÂéÂÂé°å²åÂÂæ¼容æÂÂ被åÂÂå¾Âä¹ÂèÂÂãÂÂ
- A9. ä¸Âå®Âå ¨çÂÂéÂÂè¨Â(Insecure Communication)ï¼Âå³éÂÂæÂÂæÂÂæ§è³ÂæÂÂæÂÂ並æª使ç¨HTTPSæÂÂå ¶ä»Âå å¯Âæ¹å¼ÂãÂÂ
- A10. çÂÂæ¼éÂÂå¶URLÃ¥ÂÂÃ¥ÂÂ(Failure to Restrict URL Access)ï¼ÂæÂÂäºÂ網é Âå çºæ²ÂæÂÂæ¬ÂéÂÂæ§å¶ï¼Â使å¾ÂæÂȾÂÂè å¯éÂÂéÂÂ網åÂÂç´æÂ¥åÂÂÃ¥ÂÂï¼Âæ¡Âä¾Âå æ¬å Â許ç´æ¥修æ¹WikiæÂÂBlog網é Â堧容ãÂÂ
éÂÂ次OWASPå ¬å¸Âæ°çÂÂTop 10Ã¥ÂÂæ åºç®åÂÂçÂÂæÂȾÂÂç¾æ³Âï¼Â以ä»Âå¹´çºä¾Âï¼ÂCross-Site Scripting(XSS)調æ´çº10大æÂȾÂÂä¹Âé¦Âï¼ÂçÂÂ實çÂÂÃ¥ÂÂæ åºç®åÂÂ網路é£éÂÂèÂÂè©Â欺çÂÂæÂȾÂÂæ¿«ç¨XSSçÂÂæ 形ï¼ÂäºÂ實ä¸Âï¼Âç¾ÂÃ¥ÂÂÃ¥ÂÂé²é¨çÂÂBSIè¨Âç«(Build-Security In,https://buildsecurityin.us-cert.gov/) Ã¥ÂÂMitreç Â究æ©Âæ§ÂçÂÂCVEè³Âå®ÂèÂÂå¼±æ§åÂÂ表(http://cve.mitre.org/) 亦顯示1)Cross Site ScriptingèÂÂ2)SQL Injectionå·²é£çºÂå ©å¹´åÂÂçº堨çÂÂé ÂèÂÂå´éÂÂè³Âå®Âå¼±é»Â.
ç´æÂ¥èÂÂç¨Âå¼Â碼å®Âå ¨åÂÂ質æÂÂéÂÂ
- [å¿ è¦Â*]A1. 跨網ç«Â堥侵åÂÂ串(Cross Site Scripting)
- [å¿ è¦Â*]A2. 注堥缺失(Injection Flaw)
- [建è°*]A3. æ¡æÂÂæªÂæ¡Âå·è¡Â(Malicious File Execution)
- [建è°*]A4. ä¸Âå®Âå ¨çÂÂç©件åÂÂèÂÂ(Insecure Direct Object Reference)
- [é¸æÂÂ*]A5. 跨網ç«Âè¦Âæ±Âå½é (Cross-Site Request Forgery)
*OWASPå°ç£åÂÂæÂÂå¼·çÂÂ建è°åÂÂå®ä½Âå¨é²è¡ÂæºÂ碼檢測æÂÂï¼Â尤以æ¿åºÂæ©ÂéÂÂ(æ§Â)ï¼ÂæÂÂéµ循æ¿åºÂè³ÂéÂÂå®ÂÃ¥Â
¨ä½Âæ¥Âè¦Âç¯Â(http://www.giscc.org.tw) ä¹ÂãÂÂWebæÂÂç¨ç¨Âå¼Âå®ÂÃ¥Â
¨åÂÂèÂÂæÂÂå¼ÂãÂÂï¼Â並å°Â1èÂÂ2Ã¥ÂÂçºå¿Â
è¦Â檢測é Â
ç®ï¼Â3èÂÂ4Ã¥ÂÂçº建è°檢測é Â
ç®ï¼ÂèÂÂ5Ã¥ÂÂçºé¸æÂÂ檢測é Â
ç®ãÂÂ
ï¼Âå¨實åÂÂæ¡Âä¾Âä¸Âï¼Â檢測並修æ£1èÂÂ2å³å¯é¿å ÂçµÂ大å¤Âæ¸çÂÂWebè³Âå®Âå¨Âè ãÂÂ
å ä¸Âè¿°æ¼Âæ´ÂéÂÂæÂ¥é æÂÂæÂÂèÂÂWeb伺æÂÂå¨åÂÂå¤Âé¨è¨Âå®ÂæÂÂéÂÂ
- Information Leakage and Improper Error Handling
- Broken Authentication and Session Management
- Insecure Cryptographic Storage
- Insecure Communications
- Failure to Restrict URL Access
æÂÂå¡åÂÂ表 (Member List)
Coming up soon!