This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org

Difference between revisions of "OWASP Code Review Guide Table of Contents"

From OWASP
Jump to: navigation, search
(Java)
m (Switched a link from article to navigation shell)
 
(115 intermediate revisions by 9 users not shown)
Line 1: Line 1:
 +
{{LinkBar
 +
  | useprev=PrevLink | prev= | lblprev=
 +
  | usemain=MainLink | main=OWASP Code Review Guide Table of Contents | lblmain=Table of Contents
 +
  | usenext=NextLink | next=Code Review Guide Foreword | lblnext=Foreword by OWASP Chair
 +
}}
 
__NOTOC__
 
__NOTOC__
  
[[Chapters Assigned|Chapters Assigned]]
+
 
 
==[[Code Review Guide Foreword|Foreword by OWASP Chair]]==
 
==[[Code Review Guide Foreword|Foreword by OWASP Chair]]==
  
==[[Code Review Guide Frontispiece |1. Frontispiece]]==
+
==Frontispiece==
  
'''[[Code Review Guide Frontispiece|1.1 About the OWASP Code Review Project]]'''
+
* [[Code Review Guide Frontispiece|About the OWASP Code Review Project]]
 +
* [[OCRG1.1:About The Open Web Application Security Project|About The Open Web Application Security Project]]
  
Copyright
+
==Guide History==
 +
* [[Code Review Guide History]]
  
Editors
+
==Methodology==
  
Authors and Reviewers
+
*[[Code Review Introduction|Introduction]]
 +
*[[Code Review Preparation|Preparation]]
 +
*[[Security Code Review in the SDLC]]
 +
*[[Security Code Review Coverage]]
 +
*[[OCRG1.1:Application Threat Modeling|Application Threat Modeling]]
 +
*[[Code Review Metrics]]
  
Revision History
+
==Crawling Code==
 +
* [[Crawling Code]]
 +
* [[Searching for Code in J2EE/Java]]
 +
* [[Searching for Code in Classic ASP]]
 +
* [[JavaScript/Web 2.0 Keywords and Pointers]]
  
Trademarks
+
==Code Reviews and PCI DSS==
 +
* [[Code Reviews and Compliance]]
  
'''[[About The Open Web Application Security Project|1.2 About The Open Web Application Security Project]]'''
+
==Examples by Technical Control==
 +
* [[Codereview-Authentication|Authentication]]
 +
* [[Codereview-Authorization|Authorization]]
 +
* [[Codereview-Session-Management|Session Management]]
 +
* [[Codereview-Input Validation|Input Validation]]
 +
* [[Codereview-Error-Handling|Error Handling]]
 +
* [[Codereview-Deployment|Secure Deployment]]
 +
* [[Codereview-Cryptographic_Controls|Cryptographic Controls]]
  
Overview
+
==Examples by Vulnerability==
 +
* [[Reviewing Code for Buffer Overruns and Overflows]]
 +
* [[Reviewing Code for OS Injection]]
 +
* [[Reviewing Code for SQL Injection]]
 +
* [[Reviewing Code for Data Validation]]
 +
* [[Reviewing Code for Cross-Site Scripting]]
 +
* [[Reviewing Code for Cross-Site Request Forgery]]
 +
* [[Reviewing Code for Logging Issues]]
 +
* [[Reviewing Code for Session Integrity]]
 +
* [[Reviewing Code for Race Conditions]]
  
Structure
+
== Language Specific Best Practice ==
  
Licensing
+
===Java===
 +
*[[Java Gotchas]]
 +
*[[Leading Java Security Practice]]
  
Participation and Membership
+
===Classic ASP===
 +
*[[Classic ASP Design Mistakes]]
  
Projects
+
===PHP===
 +
*[[Leading PHP Security Practice]]
  
OWASP Privacy Policy
+
===C/C++===
 +
*[[Strings and Integers]]
  
 +
===MySQL===
 +
*[[Reviewing MySQL Security]]
  
==Guide History==
+
===Rich Internet Applications===
[[Long long ago...]]
+
*[[Reviewing Flash Applications]]
 +
*[[Reviewing AJAX Applications]]
 +
*[[Reviewing Web Services]]
  
==Methodology==
+
== Example Reports ==
 +
* [[How to Write an Application Code Review Finding]]
  
#[[Code Review Introduction|Introduction]]
+
==Automating Code Reviews==
#[[Steps and Roles]]
+
* [[Automated Code Review]]
#[[Code Review Processes]]
+
* [[Tool Deployment Model]]
#[[Transaction Analysis]]
+
* [[Code Auditor Workbench Tool]]
[[Category:OWASP Code Review Project]]
+
* [[The Owasp Orizon Framework]]
  
== Design review ==
+
==[[The Owasp Code Review Top 9]]==
#[[Designing for security]]
 
##[[.NET]]
 
##[[Java]]
 
##[[PHP]]
 
##[[C]]
 
##[[C++]]
 
##[[MySQL]]
 
##[[AJAX]]
 
  
==Examples by Vulnerability==
+
==[[The Owasp Code Review Scoring System]]==
#[[Reviewing Code for Buffer Overruns and Overflows]]
 
#[[Reviewing Code for OS Injection]]
 
#[[Reviewing Code for SQL Injection]]
 
#[[Reviewing Code for Data Validation]]
 
#[[Reviewing code for XSS issues]]
 
#[[Reviewing code for CSRF issues]]
 
#[[Reviewing Code for Error Handling]]
 
#[[Reviewing Code for Logging Issues]]
 
#[[Reviewing The Secure Code Environment]]
 
#[[Reviewing Code for Authorization Issues]]
 
#[[Reviewing Code for Authentication]]
 
#[[Reviewing Code for Session Integrity issues]]
 
#[[Reviewing Cryptographic Code]]
 
#[[Reviewing Code deployment: Dangerous HTTP Methods]]
 
#[[Reviewing Code for Race Conditions]]
 
  
== Language specific best practice ==
+
==[[References]]==
  
===Java===
+
{{LinkBar
#[[Java overview]]
+
  | useprev=PrevLink | prev= | lblprev=
#[[Java gotchas]]
+
  | usemain=MainLink | main=OWASP Code Review Guide Table of Contents | lblmain=Table of Contents
#[[Java applet code review]]
+
  | usenext=NextLink | next=Code Review Guide Foreword | lblnext=Foreword by OWASP Chair
#[[Java server (J2EE) code review]]
+
}}
 
 
===.NET===
 
 
 
===PHP===
 
 
 
===C===
 
#[[Memory management]]
 
#[[String management]]
 
#[[Secure access to file system items]]
 
 
 
===RUBY===
 
 
 
==[[Automating Code Reviews]]==
 
#[[Preface ]]
 
#[[Reasons for using automated tools]]
 
#[[Education and cultural change]]
 
#[[Tool Deployment Model]]
 
#[[Code Auditor Workbench Tool]]
 
 
 
==[[References]]==
 
  
 
[[Category:OWASP Code Review Project]]
 
[[Category:OWASP Code Review Project]]

Latest revision as of 15:27, 9 September 2010

[This is the first page] Principal
(Table of Contents)

»»Foreword by OWASP Chair»»


Foreword by OWASP Chair

Frontispiece

Guide History

Methodology

Crawling Code

Code Reviews and PCI DSS

Examples by Technical Control

Examples by Vulnerability

Language Specific Best Practice

Java

Classic ASP

PHP

C/C++

MySQL

Rich Internet Applications

Example Reports

Automating Code Reviews

The Owasp Code Review Top 9

The Owasp Code Review Scoring System

References

[This is the first page] Principal
(Table of Contents)

»»Foreword by OWASP Chair»»