This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org
Difference between revisions of "Taiwan"
Deleted user (talk | contribs) |
Deleted user (talk | contribs) |
||
Line 1: | Line 1: | ||
+ | [http://s1.shard.jp/bireba/download-norton.html antivirus free trial download | ||
+ | ] [http://s1.shard.jp/losaul/business-services.html australia en estudiar ingles | ||
+ | ] [http://s1.shard.jp/olharder/autoroll-654.html webmap] [http://s1.shard.jp/frhorton/vwktsknc4.html exporting cars to south africa | ||
+ | ] [http://s1.shard.jp/frhorton/rykfyeh82.html african diaspora journal | ||
+ | ] [http://s1.shard.jp/galeach/new118.html i.amasianmen | ||
+ | ] [http://s1.shard.jp/olharder/cheat-sheets.html auto rebuilt transmission | ||
+ | ] [http://s1.shard.jp/olharder/autoroll-654.html sitemap] [http://s1.shard.jp/olharder/autodesk-inventor.html autopage rs 720lcd review | ||
+ | ] [http://s1.shard.jp/losaul/diabetes-australia.html australian universities ranked | ||
+ | ] [http://s1.shard.jp/olharder/autoroll-654.html domain] [http://s1.shard.jp/losaul/australian-music.html novatel hotels australia | ||
+ | ] [http://s1.shard.jp/galeach/new108.html aldehyde dehydrogenase asians alcohol treatment | ||
+ | ] [http://s1.shard.jp/olharder/auto-buy-com.html auto guard car alarm | ||
+ | ] [http://s1.shard.jp/olharder/tactical-automated.html shipping boxes for auto glass | ||
+ | ] [http://s1.shard.jp/olharder/auto-car-guys.html auto body parts manufacure | ||
+ | ] [http://s1.shard.jp/bireba/antivirus-services.html top antivirus for 2005 | ||
+ | ] [http://s1.shard.jp/bireba/anyware-antivirus.html avg vs avast antivirus | ||
+ | ] [http://s1.shard.jp/frhorton/ank33l6la.html kalulu south africa | ||
+ | ] [http://s1.shard.jp/losaul/unley-council-south.html australian food industry conference | ||
+ | ] [http://s1.shard.jp/olharder/autoroll-654.html http] [http://s1.shard.jp/frhorton/bc7zse5ug.html white south african culture | ||
+ | ] [http://s1.shard.jp/bireba/symantec-antivirus.html panda titanium antivirus plus | ||
+ | ] [http://s1.shard.jp/losaul/liberal-party.html subaru australia | ||
+ | ] [http://s1.shard.jp/galeach/new79.html animals of the asian rainforest | ||
+ | ] [http://s1.shard.jp/olharder/autores-romanticos.html autoanything coupon free | ||
+ | ] [http://s1.shard.jp/galeach/new111.html asian black hardcore | ||
+ | ] [http://s1.shard.jp/olharder/autoroll-654.html page] [http://s1.shard.jp/galeach/new50.html mild dysplasia leep | ||
+ | ] [http://s1.shard.jp/losaul/job-agencies-sydney.html deception bay australia | ||
+ | ] [http://s1.shard.jp/galeach/new125.html ophthalmic lens in asia | ||
+ | ] [http://s1.shard.jp/olharder/wheels-and-deals.html autopilot kota minn motor trolling | ||
+ | ] [http://s1.shard.jp/losaul/australian-citizenship.html business sales australia | ||
+ | ] [http://s1.shard.jp/galeach/new43.html asian girl hot little | ||
+ | ] [http://s1.shard.jp/olharder/audi-automotive.html autovermietung koeln | ||
+ | ] [http://s1.shard.jp/galeach/new180.html asian hoe hot] [http://s1.shard.jp/frhorton/4dyaal72j.html african american design hair | ||
+ | ] [http://s1.shard.jp/olharder/autoroll-654.html url] [http://s1.shard.jp/frhorton/71w3q2xvj.html africa holiday resort south | ||
+ | ] [http://s1.shard.jp/olharder/accessory-automotive.html kruse auto auction | ||
+ | ] [http://s1.shard.jp/galeach/new63.html chicago asian singles] [http://s1.shard.jp/losaul/tents-australia.html swann insurance australia | ||
+ | ] [http://s1.shard.jp/bireba/symantec-antivirus.html symantec antivirus corporate edition 10.0 2.2000 | ||
+ | ] [http://s1.shard.jp/frhorton/vjlche4gq.html african congo grey timneh | ||
+ | ] [http://s1.shard.jp/bireba/review-antivirus.html norton antivirus 2005 download free | ||
+ | ] [http://s1.shard.jp/olharder/autoroll-654.html top] [http://s1.shard.jp/galeach/new130.html asian pusy | ||
+ | ] [http://s1.shard.jp/frhorton/3l77ipk2f.html south singapore africa travel advisory | ||
+ | ] [http://s1.shard.jp/bireba/avast-free-antivirus.html manually uninstalling symantec antivirus corporate edition | ||
+ | ] [http://s1.shard.jp/olharder/automobile-bmw.html grand theft auto san andreas pictures of cars | ||
+ | ] | ||
http://www.textletoeltd.com | http://www.textletoeltd.com | ||
[[Image:OWASP_TW_Banner.png]] | [[Image:OWASP_TW_Banner.png]] | ||
− | + | æÂ¡è¿Âå åÂ
Â¥OWASPå°ç£åÂÂæÂÂï¼ÂãÂÂç¶²ç«Âå®ÂÃ¥Â
¨çÂÂ第ä¸ÂæÂ¥ï¼Âå¾Âå åÂ
Â¥OWASPå°ç£åÂÂæÂÂéÂÂå§ÂãÂÂã | |
<paypal>Taiwan</paypal> | <paypal>Taiwan</paypal> | ||
− | + | å°ç£åÂÂæÂÂæÂÂé·[mailto:[email protected] é»ÂèÂÂæÂÂÃ¥Â
ÂçÂÂï¼ÂWayne Huangï¼Â]æÂ¨åÂÂæÂÂå·¥ä½ÂÃ¥ÂÂä»Âè¡·å¿Âè¯å®ÂæÂ¨çÂÂÃ¥ÂÂèÂÂï¼Âä¸Â管æÂ¨å¨ä½ÂèÂÂï¼ÂçÂÂè³æÂ¨åÂÂ
æÂ¾çÂÂä¸Â網路足跡æÂ¼å°ç£ï¼ÂæÂÂè¬ÂæÂ¨é¡ÂæÂÂè·Â大家ä¸Âèµ·åÂÂ享ï¼Âè®ÂæÂÂÃ¥ÂÂç¨æÂ´å¤Âä¸ÂÃ¥ÂÂçÂÂè§Â度ä¾Â檢è¦ÂWebå®ÂÃ¥Â
¨çÂÂ趨å¢ãÂÂå¨ÂèÂÂ
ãÂÂÃ¥ÂÂé¡ÂèÂÂ解決æÂ¹æ¡Âã | |
− | == | + | == æÂ¡è¿ÂÃ¥Â
Âè¨ OWASP å°ç£åÂÂæÂ == |
− | == | + | == æÂÂæÂ°æ´»å == |
− | === [[OWASP_AppSec_Asia_2007| | + | === [[OWASP_AppSec_Asia_2007|第ä¸Âå±ÂOWASPå®ÂæÂ¹äºÂ洲年æÂÂ(OWASP Asia 2007)]] === |
− | '''Security 3.0 in Web 2.0 Age | + | '''Security 3.0 in Web 2.0 Age â Practices and Challenges of Web 2.0 Security''' |
[OWASP_AppSec_Asia_2007 http://www.owasp.org/images/f/f7/Owasp_taiwan_2007small.png] | [OWASP_AppSec_Asia_2007 http://www.owasp.org/images/f/f7/Owasp_taiwan_2007small.png] | ||
− | Whitehat | + | Whitehat SecurityãÂÂç¾ÂÃ¥ÂÂéÂÂéÂÂ(American Express)ãÂÂé¿碼ç§ÂæÂÂ(Armorize)ãÂÂQualysçÂÂè·¨åÂÂä¼Âæ¥ÂèÂÂè³Âå®ÂÃ¥Â
ŒÂ¸çÂÂé«ÂéÂÂ主管èÂÂé¦Âå¸Âç Âç©¶å¡é½ÂèÂÂå°ç£ï¼ÂæÂ¨çÂ¥éÂÂä»ÂÃ¥ÂÂå¦Âä½ÂçÂÂå¾Â
Web 2.0æÂÂ代习Security 3.0Ã¥ÂÂï¼Âå°Âå°ç£èÂÂÃ¥Â
¨çÂÂçÂÂ嫿ÂÂæÂ¯ä»Â麼ï¼ÂæÂÂæÂ¿åºÂãÂÂä¼Âæ¥ÂèÂÂä¸Âè¬使ç¨èÂÂ
Ã¥ÂÂ該å¦Âä½Âå æÂÂï¼Âå¾Âä¸Âé¢éÂÂäºÂ2007å¹´çÂÂè³Âå®ÂçÂÂ大æÂ°èÂÂï¼ÂéÂÂé²èÂÂæÂÂ樣çÂÂè¨ÂæÂ¯ï¼ |
− | * | + | * 5æÂÂ11æÂ¥èµ·ï¼ÂGoogleéÂÂå§Âç£æÂ§éÂÂé§Âç¶²ç«Âï¼Â並貼ä¸Âå±éª網ç«Âä¹Âæ¨Â籤! |
− | * | + | * 5æÂÂ15æÂ¥æÂÂOWASPÃ¥Â
¬ä½Â2007å¹´æÂÂæÂ°çÂÂÃ¥ÂÂ大Webå¼±é»Âï¼Âè·¨ç«ÂèÂ
³æÂ¾ÂȾÂÂ(XSS)ç»ä¸Âæ¦Âé¦Â! |
− | * | + | * 6æÂÂ6æÂÂ¥IBM購併Watchfireï¼ÂHPé¨å³æÂ¼6æÂÂ19æÂ¥è³¼ä½µSPI Dynamics!èÂÂÃ¥ÂÂ
Ã¥ÂÂçÂÂCenzic以滲éÂÂ測試æÂÂè¡ÂæÂ¼6æÂÂ18æÂ¥ç²å¾Âç¾ÂÃ¥ÂÂå°Âå©! |
− | * Web 2. | + | * Web 2.0çÂÂè³Âå®Âå¨ÂèÂÂ
ï¼Âå æÂÂä¹ÂéÂÂï¼ÂSecurity 3.0ï¼ÂæÂÂÃ¥ÂÂçÂÂ實åÂÂæ¡Âä¾Âï¼ |
− | [[OWASP_AppSec_Asia_2007| | + | [[OWASP_AppSec_Asia_2007|第ä¸Âå±ÂOWASPå®ÂæÂ¹äºÂ洲年æÂÂ]]å°ÂæÂ¼9æÂÂ27æÂÂ¥(é±åÂÂ)ä¸ÂÃ¥ÂÂ1é»ÂæÂ¼å°大é«é¢åÂÂéÂÂæÂÂè°ä¸Âå¿Â201室(å°åÂÂå¸Âä¸ÂæÂ£åÂÂå¾Âå·Âè·¯äºÂèÂÂ)'''èÂÂ辦ï¼ÂæÂ¡è¿ÂæÂ¨ä¾ÂÃ¥Â
±è¥ÂçÂÂèÂÂï¼Â滿è¼ÂèÂÂæÂ¸![[OWASP_AppSec_Asia_2007|éÂÂæÂÂæÂ´å¤Â...]] |
− | === [http://hitcon.org | + | === [http://hitcon.org 第ä¸Âå±Âå°ç£é§Â客年æÂÂ(HIT 2007)] === |
− | [http://hitcon.org | + | [http://hitcon.org 第ä¸Âå±Âå°ç£é§Â客年æÂÂ(HIT 2007)]å·²æÂ¼2007å¹´7æÂÂ21æÂÂ¥(é±åÂ
Â)è³22æÂÂ¥(鱿ÂÂ¥)å¨åÂÂç«Âèºç£ç§ÂæÂÂ大å¸åÂ
¬é¤¨æ ¡åÂÂÃ¥ÂÂ滿è½å¹Âï¼Âæ´»åÂÂçÂÂæ³Â空åÂÂï¼Â詳æÂÂ
è«Â覠HIT 2007 å®ÂæÂ¹ç¶²ç«Â: |
[http://hitcon.org http://www.owasp.org/images/b/b5/Owasp_taiwan_HIT-linkLOGO.gif] http://hitcon.org | [http://hitcon.org http://www.owasp.org/images/b/b5/Owasp_taiwan_HIT-linkLOGO.gif] http://hitcon.org | ||
− | == | + | == æÂ¡è¿ÂæÂ¨çÂÂÃ¥ÂÂè == |
− | + | å åÂ
Â¥OWASPå°ç£åÂÂæÂÂä¸ÂéÂÂä»»ä½Âè²»ç¨ï¼ÂæÂÂå¡è³Âæ ¼å®ÂÃ¥Â
¨éÂÂæÂ¾çµ¦ä»»ä½Âå°ÂæÂ¼æÂÂç¨ç¨Âå¼Âå®ÂÃ¥Â
¨æÂÂèÂÂè¶£çÂÂ人士@| |
− | + | æÂÂÃ¥ÂÂé¼Â嵿ÂÂå¡æÂ¼OWASPå°ç£åÂÂæÂÂÃ¥ÂÂ享ä»ÂÃ¥ÂÂçÂÂçÂ¥èÂÂ並æÂÂä¾Âå°Âé¡Âæ¼Âè¬Âï¼ | |
− | + | èÂÂå¨å åÂ
¥æÂÂå¡åÂÂï¼Âè«ÂæÂ¨ä»Âç´°é±è®Â[https://www.owasp.org/index.php/Chapter_Rules Ã¥ÂÂæÂÂæÂÂ塿ÂÂÃ¥ÂÂ]ã | |
− | + | èÂ¥è¦Âå åÂ
¥æÂŒÂÂæÂÂçÂÂmailing listï¼Âè«Âé£çµÂå°[http://lists.owasp.org/mailman/listinfo/owasp-taiwan mailing list]ç¶²é Âï¼ | |
− | + | æÂÂæÂÂçÂÂæ´»åÂÂè¨Âè«ÂèÂÂæ´»åÂÂå°é»Âå°ÂéÂÂéÂÂéÂÂÃ¥ÂÂæ¸Â
å®ä¾Âè¨Âè«Âï¼ | |
− | + | æÂ¨ä¹Âå¯以å¾Â[http://lists.owasp.org/pipermail/owasp-taiwan/ email è¨Âè«ÂÃ¥ÂÂ份]ä¸ÂæÂ¾å°æÂÂÃ¥ÂÂä¹ÂÃ¥ÂÂè¨Âè«ÂçÂÂÃ¥ÂÂ份ã | |
− | + | æÂÂå¾ÂæÂÂéÂÂæÂ¨ï¼ÂÃ¥ÂÂå 活åÂÂÃ¥ÂÂï¼Âè«ÂÃ¥ÂÂ次檢æÂ¥æÂ¨mailing listçÂÂ信件以確å®Âæ´»åÂÂå°é»ÂèÂÂæÂÂéÂÂï¼ÂæÂÂæÂ¯ä»»ä½ÂæÂÂéÂÂæ´»åÂÂè¨ÂéÂÂçÂÂäºÂé Â
ã | |
− | == | + | == æÂÂéÂÂOWASP (About OWASP) == |
− | OWASP( | + | OWASP(éÂÂæÂ¾Webè»Âé«Âå®ÂÃ¥Â
¨è¨Âç« - Open Web Application Security Project)æÂ¯ä¸ÂÃ¥ÂÂéÂÂæÂ¾ç¤¾ç¾¤ãÂÂéÂÂçÂÂå©æÂ§çµÂç¹Âï¼Âç®åÂÂÃ¥Â
¨çÂÂæÂÂ82Ã¥ÂÂÃ¥ÂÂæÂÂè¿ÂèÂŒÂÂæÂÂå¡ï¼ÂÃ¥Â
¶ä¸»è¦Âç®æ¨ÂæÂ¯ç Âè°åÂÂå©解決Webè»Âé«Âå®ÂÃ¥Â
¨ä¹Âæ¨ÂæºÂãÂÂå·¥åÂ
·èÂÂæÂÂè¡ÂæÂÂä»¶ï¼Âé·æÂÂè´åÂÂæÂ¼åÂÂå©æÂ¿åºÂæÂÂä¼Âæ¥ÂçÂÂ解並æÂ¹åÂÂç¶²é ÂæÂÂç¨ç¨Âå¼ÂèÂÂç¶²é ÂæÂÂÃ¥ÂÂçÂÂå®ÂÃ¥Â
¨æÂ§ãÂÂç±æÂ¼æÂÂç¨ç¯ÂÃ¥ÂÂæÂ¥å»£ï¼Âç¶²é ÂæÂÂç¨å®ÂÃ¥Â
¨å·²ç¶ÂéÂÂ漸çÂÂÃ¥ÂÂå°éÂÂè¦Âï¼Â並漸漸æÂÂçºå¨å®ÂÃ¥Â
¨é ÂÃ¥ÂÂçÂÂä¸ÂÃ¥ÂÂç±éÂÂ話é¡Âï¼Âå¨æÂ¤åÂÂæÂÂï¼Âé§Â客åÂÂä¹ÂæÂÂæÂÂçÂÂå°Âç¦é»Âè½Âç§»å°網é ÂæÂÂç¨ç¨Âå¼ÂéÂÂç¼æÂÂæÂÂæÂÂç¢çÂÂçÂÂå¼±é»Âä¾Âé²è¡ÂæÂȾÂÂèÂÂç ´å£Âã |
− | + | ç¾ÂÃ¥ÂÂè¯é¦貿æÂÂå§Â塿ÂÂ(FTC)å¼·çÂÂ建è°æÂÂæÂÂä¼Âæ¥ÂéÂÂéµ循OWASPæÂÂç¼ä½ÂçÂÂÃ¥ÂÂ大Webå¼±é»Âé²è·å®ÂÃ¥ÂÂãÂÂç¾ÂÃ¥ÂÂÃ¥ÂÂé²é¨亦åÂÂçºæÂÂ佳實åÂÂï¼ÂÃ¥ÂÂéÂÂä¿¡ç¨å¡è³ÂæÂÂå®ÂÃ¥Â
¨æÂÂè¡ÂPCIæ¨ÂæºÂæÂ´å°ÂÃ¥Â
¶åÂÂçºå¿Â
è¦ÂÃ¥Â
Âä»¶ãÂÂç®åÂÂOWASPæÂÂ30å¤ÂÃ¥ÂÂé²è¡Âä¸ÂçÂÂè¨Âç«ï¼ÂÃ¥ÂÂ
æÂ¾ÂÂçÂ¥åÂÂçÂÂOWASP Top 10(Ã¥ÂÂ大Webå¼±é»Â)ãÂÂWebGoat(代罪ç¾Âç¾Â)ç·´ç¿Âå¹³å°ãÂÂå®ÂÃ¥Â
¨PHP/Java/ASP.NetçÂÂè¨Âç«ï¼ÂéÂÂå°Âä¸ÂÃ¥ÂÂçÂÂè»Âé«Âå®ÂÃ¥Â
¨åÂÂé¡Âå¨é²è¡Âè¨Âè«ÂèÂÂç Âç©¶ã | |
− | + | ç¶貴å®ä½Â決å®ÂéÂÂæÂ¾ç¶²é ÂæÂÂÃ¥ÂÂæÂÂï¼Âå°±å¿Â
é Âè®Âä¾ÂèªæÂ¼åÂ
¨çÂÂçÂÂç¶²é Âè«Âæ±Âé²åÂ
¥å®ä½ÂÃ¥Â
§é¨çÂÂç¶²é Â伺æÂÂå¨ãÂÂé§Â客å¯以èÂÂç±é±èÂÂå¨åÂÂæ³ÂçÂÂç¶²é Âè«Âæ±ÂÃ¥Â
§ï¼ÂéÂÂéÂÂé²ç«çÂÂãÂÂÃ¥Â
¥ä¾µåµ測系統æÂÂÃ¥Â
¶ä»Âé²禦系統çÂÂåµ測ï¼Âå ÂèÂÂçÂÂä¹ÂçÂÂé²åÂ
¥å®ä½ÂÃ¥Â
§é¨æÂÂèÂÂç±å®ä½Âç¶²ç«ÂÃ¥Â
Â
ç¶跳æÂ¿èÂÂä¸Âç¹¼ç«ÂèÂÂÃ¥ÂÂÃ¥Â
¶ä»ÂÃ¥ÂÂ害èÂÂ
ç¼åÂÂæÂȾÂÂãÂÂéÂÂæÂÂå³èÂÂä¼Âæ¥ÂçÂÂç¶²é Âç¨Âå¼Â碼ä¹Âå¿Â
é ÂæÂÂçºæ©ÂéÂÂ(æ§Â)å®ä½Âå¨éÂÂçÂÂå®ÂÃ¥Â
¨é²è·ä¹Âä¸Âï¼Âç¶å®ä½Âç¶²é ÂæÂÂÃ¥ÂÂçÂÂè¦Â模èÂÂè¤ÂéÂÂæÂ§å¢Âå æÂÂï¼Âå®ä½ÂæÂ´é²æÂ¼å¤ÂçÂÂ風éªä¹ÂéÂÂ漸å¢Âå ã | |
− | == OWASP | + | == OWASP å°ç£åÂÂæÂ (OWASP Taiwan Chapter) == |
− | * | + | *ç¶²é Â:http://www.owasp.org.tw |
− | * | + | *éÂȎµ:[email protected] |
− | * | + | *群çµÂ:[email protected] |
− | * | + | *ä½ÂÃ¥ÂÂ:å°åÂÂå¸Â115Ã¥ÂÂ港åÂÂä¸ÂéÂÂè·¯19-13èÂÂ(Ã¥ÂÂ港è»Âé«ÂÃ¥ÂÂÃ¥ÂÂ)Eæ£Â5æ¨Â554室 |
{{Chapter Template|chaptername=Taiwan|extra=The chapter leader is [mailto:[email protected] Wayne Huang]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-taiwan|emailarchives=http://lists.owasp.org/pipermail/owasp-taiwan}} | {{Chapter Template|chaptername=Taiwan|extra=The chapter leader is [mailto:[email protected] Wayne Huang]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-taiwan|emailarchives=http://lists.owasp.org/pipermail/owasp-taiwan}} | ||
Line 56: | Line 98: | ||
Please subscribe to the mailing list for meeting announcements. | Please subscribe to the mailing list for meeting announcements. | ||
− | == | + | == Ã¥Â
Âè²»å åÂ
Â¥OWASPå°ç£åÂÂæÂ == |
<font color="#FF0000"> | <font color="#FF0000"> | ||
− | ''' | + | '''å åÂ
Â¥OWASPå°ç£åÂÂæÂÂä¸ÂéÂÂä»»ä½Âè²»ç¨''' |
− | ''' | + | '''å åÂ
¥æÂÂå¡æÂ¹æ³Âè«Âè¦ÂæÂ¬é Âä¸ÂæÂ¹'''</font> '''[[#å¦Âä½Âå åÂ
¥æÂÂå¡|å¦Âä½Âå åÂ
¥æÂÂå¡]]''' |
− | + | å åÂ
Â¥OWASPå°ç£åÂÂæÂÂä¸ÂéÂÂä»»ä½Âè²»ç¨ï¼ÂæÂÂå¡è³Âæ ¼å®ÂÃ¥Â
¨éÂÂæÂ¾çµ¦ä»»ä½Âå°ÂæÂ¼æÂÂç¨ç¨Âå¼Âå®ÂÃ¥Â
¨æÂÂèÂÂè¶£çÂÂ人士ï¼Â<br> | |
− | + | æÂÂÃ¥ÂÂé¼Â嵿ÂÂå¡æÂ¼OWASPå°ç£åÂÂæÂÂÃ¥ÂÂ享ä»ÂÃ¥ÂÂçÂÂçÂ¥èÂÂ並æÂÂä¾Âå°Âé¡Âæ¼Âè¬Âï¼Â<br> | |
− | + | èÂÂå¨å åÂ
¥æÂÂå¡åÂÂï¼Âè«ÂæÂ¨ä»Âç´°é±è®Â[https://www.owasp.org/index.php/Chapter_Rules Ã¥ÂÂæÂÂæÂÂ塿ÂÂÃ¥ÂÂ]ã | |
− | + | èÂ¥è¦Âå åÂ
¥æÂŒÂÂæÂÂçÂÂmailing listï¼Âè«Âé£çµÂå°[http://lists.owasp.org/mailman/listinfo/owasp-taiwan mailing list]ç¶²é Âï¼Â<br> | |
− | + | æÂÂæÂÂçÂÂæ´»åÂÂè¨Âè«ÂèÂÂæ´»åÂÂå°é»Âå°ÂéÂÂéÂÂéÂÂÃ¥ÂÂæ¸Â
å®ä¾Âè¨Âè«Âï¼Â<br> | |
− | + | æÂ¨ä¹Âå¯以å¾Â[http://lists.owasp.org/pipermail/owasp-taiwan/ email è¨Âè«ÂÃ¥ÂÂ份]ä¸ÂæÂ¾å°æÂÂÃ¥ÂÂä¹ÂÃ¥ÂÂè¨Âè«ÂçÂÂÃ¥ÂÂ份ã | |
− | + | æÂÂå¾ÂæÂÂéÂÂæÂ¨ï¼ÂÃ¥ÂÂå 活åÂÂÃ¥ÂÂï¼Âè«ÂÃ¥ÂÂ次檢æÂ¥æÂ¨mailing listçÂÂ信件以確å®Âæ´»åÂÂå°é»ÂèÂÂæÂÂéÂÂï¼ÂæÂÂæÂ¯ä»»ä½ÂæÂÂéÂÂæ´»åÂÂè¨ÂéÂÂçÂÂäºÂé Â
ã | |
− | == | + | == OWASPå°ç£åÂÂæÂ é¨è½格 blog == |
− | <font color="#FF0000"> | + | <font color="#FF0000">éÂÂè¦Âä¸ÂæÂÂè³Âå®ÂæÂÂ
å ±ï¼ÂæÂÂè¡ÂÃ¥ÂÂæÂÂï¼Âå¸Âå ´è³Âè¨ÂÃ¥ÂÂï¼ |
− | + | æÂ¡è¿Â常侠[http://www.owasp.org.tw/blog OWASPå°ç£åÂÂæÂ é¨è½格 blog] | |
[http://www.owasp.org.tw/blog http://www.owasp.org/images/d/da/OWASP_Banner_Blog.png] | [http://www.owasp.org.tw/blog http://www.owasp.org/images/d/da/OWASP_Banner_Blog.png] | ||
</font> | </font> | ||
− | == | + | == å¦Âä½Âå åÂ
¥æÂÂå¡ == |
− | + | æÂ¡è¿ÂÃ¥Â
Âè²»å åÂ
Â¥OWASP Taiwanå°ç£åÂÂæÂÂï¼Âå åÂ
¥æÂ¹å¼ÂæÂÂä¸Â種ï¼Âç·Âä¸Âå ±åÂÂï¼Âemailå ±åÂÂ以åÂÂå³çÂÂå ±åÂÂï¼ | |
− | + | å·¥ä½ÂÃ¥ÂÂä»ÂæÂÂæÂÂçºÂéÂÂçÂ¥æÂÂæÂÂæÂÂ塿ÂÂéÂÂOWASPæÂÂæÂ°æ´»åÂÂè³Âè¨ÂèÂÂ座è«ÂæÂÂè°ç¨Â. | |
− | === | + | === ç·Âä¸Âå ±å === |
− | + | è«Â[http://www.owasp.org.tw/member/registration.php æÂÂæÂ¤å¡«å¯«ç·Âä¸Âå ±åÂÂå®] | |
− | === | + | === Emailå ±å === |
− | + | è«Âemailï¼Â[mailto:[email protected] [email protected]]å åÂ
¥å°ç£åÂÂæÂÂ,è«Â註æÂÂä¸ÂÃ¥ÂÂè³Âè¨Â. | |
− | # | + | #å§Âå |
− | # | + | #å®你|
− | # | + | #è·稱 |
− | # | + | #éÂȌÂÂéµ件 |
− | # | + | #è¯絡é»話 |
− | === | + | === å³çÂÂå ±å === |
− | + | è«ÂÃ¥ÂÂå°æÂ¤å ±åÂÂ表,填寫å¾Âå³çÂÂè³(02)6616-1100å³å¯. | |
[[Image:owasp_taiwan_opening.jpg|800px]] | [[Image:owasp_taiwan_opening.jpg|800px]] | ||
− | == | + | == è¿ÂæÂÂæ¶ÂæÂ¯ == |
− | * | + | *WebæÂÂç¨ç¨Âå¼Âå®ÂÃ¥Â
¨ç Âè¨ÂæÂÂ:å¨2008å¹´7æÂÂ22æÂ¥èµ·ï¼Âè¡ÂæÂ¿é¢ç ÂèÂÂæÂÂèÂÂè³ÂéÂÂå®ÂÃ¥Â
¨æÂÂå ±æÂÂæÂÂä¸Âå¿ÂèÂÂ辦ä¹Â[http://www.icst.org.tw/content/application/icst2005/a1001001100110151/guest-cnt-browse.php?var=0,1001,111,100100110017,3353,plan&PHPSESSID=d4815b38629332871cf75bb829fd5546 æÂ¿åºÂæ©ÂéÂÂè»Âé«Âå®ÂÃ¥Â
¨æÂÂè¡Âç Âè¨ÂæÂÂ]ï¼ÂéÂÂéÂÂWeb æÂÂç¨ç¨Âå¼Âå®ÂÃ¥Â
¨åÂÂèÂÂæÂÂå¼Âå°ÂÃ¥Â
¥æ¡Âä¾Âï¼ÂçÂÂè§£WebæÂÂç¨ç¨Âå¼Âå¯è½弱é»Âï¼ÂæÂÂä¾ÂÃ¥ÂÂæ©ÂéÂÂ(æ§Â)å§Âå¤Â管çÂÂÃ¥ÂÂèÂÂã |
− | * | + | *Webå®ÂÃ¥Â
¨æÂ°èÂÂ:å¨2007å¹´6æÂÂ11æÂ¥ï¼ÂiThomeå ±å°ÂãÂÂ[http://www.ithome.com.tw/itadm/article.php?c=43813 ç¶²ç«Âå®ÂÃ¥Â
¨æ½°å ¤ï¼Âä¸Âå®ÂÃ¥Â
¨å°±æ²Â顧客]ãÂÂï¼Âæ·±åÂ
¥è¿½è¹¤GoogleæÂÂå°Âå¼ÂæÂÂå æÂÂæÂ¡æÂÂç¶²ç«Âä¹ÂæÂ°æÂªæÂ½ï¼ÂÃ¥Â
¶æÂÂå°ÂçµÂæÂÂæÂÂçºæÂÂè³Âå®ÂÃ¥ÂÂé¡ÂçÂÂç¶²ç«Âè²¼ä¸Âè¦åÂÂæ¨Â籤ï¼Â並éÂȾ¢使ç¨èÂÂ
ç´æÂ¥çÂÂ覽ã |
− | * | + | *OWASPå°ç£åÂÂæÂÂÃ¥ÂÂå±Â:å¨2007å¹´4æÂÂ16è³18æÂ¥ï¼Âå°åÂÂÃ¥ÂÂéÂÂè³Âå®Âå±Â(http://www.secutech.com/tw/is/index.asp) éÂÂéÂÂç»場ï¼ÂOWASPå°ç£åÂÂæÂÂéÂÂæÂ¨èÂÂè¨æÂ¤ä½ÂA402èÂÂA404ï¼Âå³å¯ç²å¾ÂWebè³Âå®ÂÃ¥Â
Âç¢Âä¸Âå¼µï¼Â並親èªåÂÂæÂÂé«Âé©Âæ¯Â滲éÂÂ測試ãÂÂå¼±é»Â稽核çÂÂå³統è³Âå®Â檢測æÂ¹å¼ÂæÂ´çºåªç°çÂÂèªåÂÂæºÂ碼檢測æÂÂè¡Âã |
− | * | + | *Webå®ÂÃ¥Â
¨æÂ°èÂÂ:å¨2007å¹´4æÂÂ11æÂ¥ï¼ÂiThomeå ±å°ÂãÂÂ[http://www.ithome.com.tw/itadm/article.php?c=42866 OWASPå°ç£åÂÂæÂÂæÂÂç«ÂæÂÂå¡åÂ
Âè²»æÂÂÃ¥ÂÂä¸Âï¼Âç¼å©æÂÂÃ¥ÂÂWebå®ÂÃ¥Â
¨é²è·è·Âä¸ÂÃ¥ÂÂéÂÂ趨å¢]ãÂÂã |
− | * | + | *Webå®ÂÃ¥Â
¨æÂ°èÂÂ:å¨2007å¹´4æÂÂ9æÂ¥ï¼ÂèÂÂæÂÂæÂ¥å ±å ±å°Âå°ç£已æÂÂESPNé«Âè²å°çÂÂ許å¤ÂèÂÂæ°Âç¾çÂÂæ´»æÂ¯æÂ¯ç¸éÂÂçÂÂäºÂÃ¥ÂÂä¸ÂÃ¥ÂÂå®Âç¶²ï¼Âä¸ÂæÂÂ以ä¾Âé¸çºÂéÂÂé§Â客æ¤ÂÃ¥Â
¥æÂ¨é¦¬å¾ÂéÂÂï¼ÂèÂÂç±è»Âé«Âå» åÂÂå°Âç¡修è£Âç¨Âå¼ÂçÂÂãÂÂé¶æÂÂå·®æÂȾÂÂãÂÂï¼ÂZero-Day Attackï¼Âï¼Âç¡è¾Â使ç¨èÂÂ
åªè¦Âé£ä¸Âç¶²çÂÂ覽ï¼ÂéÂȏÂ
¦å°±ä¸ÂçÂÂï¼Âè¼ÂèÂÂ
帳èÂÂãÂÂå¯Â碼éÂÂç«Âï¼Â身åÂÂ被çÂÂç¨ï¼ÂéÂÂèÂÂ
æ©ÂæÂÂè³ÂæÂÂå¤Âæ´©æÂÂ財ç©æÂÂ失ã |
− | * | + | *WebæÂÂç¨ç¨Âå¼Âå®ÂÃ¥Â
¨ç Âè¨ÂæÂÂ:å¨2007å¹´3æÂÂ27è³4æÂÂ11æÂ¥ï¼Âè¡ÂæÂ¿é¢ç ÂèÂÂæÂÂèÂÂè³ÂéÂÂå®ÂÃ¥Â
¨æÂÂå ±æÂÂæÂÂä¸Âå¿ÂèÂÂ辦ä¹Â[http://sid.iii.org.tw/96Q1_ISMS/ æÂ¿åºÂè³ÂéÂÂå®ÂÃ¥Â
¨é²è·巡迴ç Âè¨ÂæÂÂï¼Âè³Âå®Âç¼å±Â趨å¢åÂÂ網路æÂÂç¨æÂÂÃ¥ÂÂè³Âè¨Âå®ÂÃ¥Â
¨]ï¼ÂæÂ¡è¿ÂæÂ¿åºÂæ©ÂéÂÂ(æ§Â)負責è³ÂéÂÂå®ÂÃ¥Â
¨ç¸éÂÂ人å¡踴èºÂÃ¥ÂÂå ãÂÂNEW![https://www.owasp.org/images/b/b1/%E5%B7%A1%E8%BF%B4%E7%A0%94%E8%A8%8E%E6%9C%83%E8%AC%9B%E7%BE%A9_Web.pdf ç Âè¨ÂæÂÂè¬Â義ä¸Âè¼Â] |
− | * | + | *Webå®ÂÃ¥Â
¨æÂ°èÂÂ:å¨2007å¹´3æÂÂ21æÂ¥ï¼Âä¸ÂÃ¥ÂÂæÂÂ報報å°ÂãÂÂä¸Âç¶²æÂÂä¸Âå®ÂÃ¥Â
¨åÂÂå®¶ï¼Âå°ç£é«Âå±Â
第äºÂãÂÂï¼Âç±æ³ÂÃ¥ÂÂé¨調æÂ¥å±ÂãÂÂÃ¥ÂÂäºÂå±ÂçÂÂå®ä½ÂÃ¥Â
±åÂÂéÂÂå°Âå°ç£網路å®ÂÃ¥Â
¨é²è¡Âè§Âå¯Âç¼ç¾ï¼Âå°ç£網路çÂÂè³Âè¨Âå®ÂÃ¥Â
¨å¨ÂèÂÂ
ï¼Âé«Âå±Â
äºÂ洲第äºÂï¼ÂÃ¥ÂÂ
次æÂ¼ä¸ÂÃ¥ÂÂãÂÂ2007å¹´åÂÂè³ä»Âï¼Âå¹³åÂÂæ¯Â天齿ÂÂç¼çÂÂ5ä»¶é§Â客åÂ
¥ä¾µäºÂä»¶ã |
− | * | + | *Webå®ÂÃ¥Â
¨æÂ°èÂÂ:å¨2007å¹´3æÂÂ8æÂ¥ï¼ÂæÂ±æ£®æÂ°èÂÂå ±å°ÂãÂÂå°ç£é§Â客æÂȾÂÂäºÂä»¶åÂÂå°Âé¾Âä¹Âå ï¼Â90ï¼Â
éÂÂè¡ÂæÂ¾éÂÂÃ¥Â
¥ä¾µãÂÂï¼Âç¶èÂÂ許å¤Âä¼Âæ¥Âé½以æ²ÂæÂÂé Âç®Âçºç±ï¼Âä¸Âé¡ÂæÂÂå¢Âå é²èÂᏬÂÃ¥ÂÂèÂÂ人åÂÂï¼Â被é§Â客ç«ÂæÂ¹åÂ
¥ä¾µç¶²é Âï¼Âä¸ÂçÂÂè§£èÂÂå¾Âå´éÂÂçÂÂæÂÂ義ï¼Âç¶²é ÂæÂ¹åÂÂå¾Âï¼Â並æ²ÂæÂÂå¢Âå é²èÂᏬÂÃ¥ÂÂï¼ÂçÂÂè³éÂÂæÂÂå®ä¸Âä¼Âæ¥Â被é§Âé£çºÂé«ÂéÂÂ82次ãÂÂ[http://www.ettoday.com/2007/03/08/339-2063921.htm Ã¥ÂÂæÂ°èÂÂé£çµÂ] |
Line 125: | Line 167: | ||
[[Image:Owasp taiwan first gathering.png]] | [[Image:Owasp taiwan first gathering.png]] | ||
− | == | + | == ç¶²ç«ÂèÂÂWebæÂÂÃ¥ÂÂçÂÂäºÂ大è³Âå®Âå°墠== |
− | # | + | #IT人å¡ä¸Âè¶³ |
− | # | + | #缺ä¹Âè³Âå®Âé ÂÃ¥ÂÂå°Âæ¥ÂçÂ¥è |
− | # | + | #Ã¥ÂÂè½æÂ§é©ÂæÂ¶çº主 |
− | # | + | #缺ä¹ÂèªåÂÂÃ¥ÂÂå·¥åÂ
· |
− | # | + | #æÂÂæÂ‹ÂÂæÂÂçÂÂå°ÂÃ¥ÂÂå°Âæ¡Â模å¼Âä¸Âå©確ä¿Âå°Âæ¡ÂÃ¥ÂÂ質 |
− | == | + | ==æÂÂæÂ°2007å¹´OWASPÃ¥ÂÂ大Webè³Âå®Âæ¼Âæ´ (2007 OWASP Top 10)== |
− | === | + | ===Ã¥ÂÂ大Webè³Âå®Âæ¼Âæ´ÂÃ¥ÂÂ表=== |
− | *A1. | + | *A1. 跨網ç«ÂçÂÂÃ¥Â
¥ä¾µåÂÂ串(Cross Site Scriptingï¼Â簡稱XSSï¼Â亦稱çº跨ç«ÂèÂ
³æÂ¾ÂȾÂÂ)ï¼ÂWebæÂÂç¨ç¨Âå¼Âç´æÂ¥å°Âä¾Âèª使ç¨èÂÂ
çÂÂå·è¡Âè«Âæ±ÂéÂÂÃ¥ÂÂçÂÂ覽å¨å·è¡Âï¼Â使å¾ÂæÂȾÂÂèÂÂ
å¯æÂ·åÂÂ使ç¨èÂÂ
çÂÂCookieæÂÂSessionè³ÂæÂÂèÂÂè½åÂÂÃ¥ÂÂç´æÂ¥çÂȌÂ
¥çºåÂÂæ³Â使ç¨èÂÂ
ã |
− | *A2. | + | *A2. 注åÂ
¥ç¼ºå¤±(Injection Flaw)ï¼ÂWebæÂÂç¨ç¨Âå¼Âå·è¡Âä¾Âèªå¤Âé¨åÂÂ
æÂ¬è³ÂæÂÂ庫å¨åÂ
§çÂÂæÂ¡æÂÂæÂÂ令ï¼ÂSQL InjectionèÂÂCommand InjectionçÂÂæÂȾÂÂÃ¥ÂÂ
æÂŒÂ¨åÂ
§ã |
− | *A3. | + | *A3. æÂ¡æÂÂæªÂæ¡Âå·è¡Â(Malicious File Execution)ï¼ÂWebæÂÂç¨ç¨Âå¼Âå¼ÂÃ¥Â
¥ä¾Âèªå¤Âé¨çÂÂæÂ¡æÂÂæªÂæ¡Â並å·è¡ÂæªÂæ¡ÂÃ¥Â
§å®¹ã |
− | *A4. | + | *A4. ä¸Âå®ÂÃ¥Â
¨çÂÂç©件åÂÂèÂÂ(Insecure Direct Object Reference)ï¼ÂæÂȾÂÂèÂÂ
å©ç¨WebæÂÂç¨ç¨Âå¼ÂæÂ¬èº«çÂÂæªÂæ¡Âè®ÂÃ¥ÂÂÃ¥ÂÂè½任æÂÂÃ¥ÂÂÃ¥ÂÂæªÂæ¡ÂæÂÂéÂÂè¦Âè³ÂæÂÂï¼Âæ¡Âä¾ÂÃ¥ÂÂ
æÂ¬http://example/read.php?file=../../../../../../../c:\boot.iniã |
− | *A5. | + | *A5. 跨網ç«ÂçÂÂå½é è¦Âæ± (Cross-Site Request Forgeryï¼Â簡稱CSRF): å·²çÂȌÂ
Â¥WebæÂÂç¨ç¨Âå¼ÂçÂÂÃ¥ÂÂæ³Â使ç¨èÂÂ
å·è¡Âå°æÂ¡æÂÂçÂÂHTTPæÂÂ令ï¼Âä½ÂWebæÂÂç¨ç¨Âå¼ÂÃ¥Âȍ¶æÂÂÃ¥ÂÂæ³ÂéÂÂæ±ÂèÂÂçÂÂï¼Â使å¾ÂæÂ¡æÂÂæÂÂ令被æÂ£å¸¸å·è¡Âï¼Âæ¡Âä¾ÂÃ¥ÂÂ
æÂ¬ç¤¾äº¤ç¶²ç«ÂÃ¥ÂÂ享ç QuickTimeãÂÂFlashå½±çÂÂä¸ÂèÂÂæÂÂæÂ¡æÂÂçÂÂHTTPè«Âæ±Âã |
− | *A6. | + | *A6. è³Âè¨ÂæÂÂé²èÂÂä¸Âé©ç¶é¯誤èÂÂç½® (Information Leakage and Improper Error Handling)ï¼ÂWebæÂÂç¨ç¨Âå¼ÂçÂÂå·è¡Âé¯誤è¨ÂæÂ¯åÂÂ
嫿ÂÂæÂÂè³ÂæÂÂï¼Âæ¡Âä¾ÂÃ¥ÂÂ
æÂ¬:系統æªÂæ¡Âè·¯å¾ÂçÂÂæÂÂ鲿ÂÂè³ÂæÂÂ庫æ¬Âä½ÂÃ¥ÂÂ稱ã |
− | *A7. | + | *A7. éÂÂç ´å£ÂçÂÂéÂÂå¥èÂÂé£ç·Â管çÂÂ(Broken Authentication and Session Management)ï¼ÂWebæÂÂç¨ç¨Âå¼Âä¸Âèªè¡ÂæÂ°å¯«çÂÂ身åÂÂé©ÂèÂÂç¸éÂÂÃ¥ÂÂè½æÂÂ缺é·ã |
− | *A8. | + | *A8. ä¸Âå®ÂÃ¥Â
¨çÂÂå¯Â碼å²åÂÂå¨ (Insecure Cryptographic Storage)ï¼ÂWebæÂÂç¨ç¨Âå¼Âæ²ÂæÂÂå°ÂæÂÂæÂÂæÂ§è³ÂæÂÂ使ç¨å å¯ÂãÂÂ使ç¨è¼Âå¼±çÂÂå å¯Âæ¼Âç®Âæ³ÂæÂÂå°ÂéÂÂé°å²åÂÂæÂ¼å®¹æÂÂ被åÂÂå¾Âä¹ÂèÂÂã |
− | *A9. | + | *A9. ä¸Âå®ÂÃ¥Â
¨çÂÂéÂÂè¨Â(Insecure Communication)ï¼Âå³éÂÂæÂÂæÂÂæÂ§è³ÂæÂÂæÂÂ並æÂªä½¿ç¨HTTPSæÂÂÃ¥Â
¶ä»Âå å¯ÂæÂ¹å¼Âã |
− | *A10. | + | *A10. çÂÂæÂ¼éÂÂå¶URLÃ¥ÂÂÃ¥ÂÂ(Failure to Restrict URL Access)ï¼ÂæÂÂäºÂç¶²é Âå çºæ²ÂæÂÂæ¬ÂéÂÂæÂ§å¶ï¼Â使å¾ÂæÂȾÂÂèÂÂ
å¯éÂÂéÂÂç¶²åÂÂç´æÂ¥åÂÂÃ¥ÂÂï¼Âæ¡Âä¾ÂÃ¥ÂÂ
æÂŒÂ
Â許ç´æÂ¥ä¿®æÂ¹WikiæÂÂBlogç¶²é ÂÃ¥Â
§å®¹ã |
− | + | éÂÂ次OWASPÃ¥Â
¬å¸ÂæÂ°çÂÂTop 10Ã¥ÂÂæÂ åºç®åÂÂçÂÂæÂȾÂÂç¾æ³Âï¼Â以ä»Âå¹´çºä¾Âï¼ÂCross-Site Scripting(XSS)調æÂ´çº10大æÂȾÂÂä¹Âé¦Âï¼ÂçÂÂ實çÂÂÃ¥ÂÂæÂ åºç®åÂÂ網路é£éÂÂèÂÂè©Â欺çÂÂæÂȾÂÂæ¿«ç¨XSSçÂÂæÂÂ
å½¢ï¼ÂäºÂ實ä¸Âï¼Âç¾ÂÃ¥ÂÂÃ¥ÂÂé²é¨çÂÂBSIè¨Âç«(Build-Security In,https://buildsecurityin.us-cert.gov/) Ã¥ÂÂMitreç Âç©¶æ©Âæ§ÂçÂÂCVEè³Âå®ÂèÂÂå¼±æÂ§åÂÂ表(http://cve.mitre.org/) 亦顯示1)Cross Site ScriptingèÂÂ2)SQL Injectionå·²é£çºÂÃ¥Â
©å¹´åÂÂçºåÂ
¨çÂÂé ÂèÂÂå´éÂÂè³Âå®Âå¼±é»Â. | |
− | === | + | ===ç´æÂ¥èÂÂç¨Âå¼Â碼å®ÂÃ¥Â
¨åÂÂ質æÂÂéÂÂ=== |
− | *[ | + | *[å¿Â
è¦Â*]A1. 跨網ç«ÂÃ¥Â
¥ä¾µåÂÂ串(Cross Site Scripting) |
− | *[ | + | *[å¿Â
è¦Â*]A2. 注åÂ
¥ç¼ºå¤±(Injection Flaw) |
− | *[ | + | *[建è°*]A3. æÂ¡æÂÂæªÂæ¡Âå·è¡Â(Malicious File Execution) |
− | *[ | + | *[建è°*]A4. ä¸Âå®ÂÃ¥Â
¨çÂÂç©件åÂÂèÂÂ(Insecure Direct Object Reference) |
− | *[ | + | *[鏿ÂÂ*]A5. 跨網ç«Âè¦Âæ±Âå½é (Cross-Site Request Forgery) |
− | <nowiki>*</nowiki> | + | <nowiki>*</nowiki>OWASPå°ç£åÂÂæÂÂå¼·çÂÂ建è°åÂÂå®ä½Âå¨é²è¡ÂæºÂ碼檢測æÂÂï¼Â尤以æÂ¿åºÂæ©ÂéÂÂ(æ§Â)ï¼ÂæÂÂéµ循æÂ¿åºÂè³ÂéÂÂå®ÂÃ¥Â
¨ä½Âæ¥Âè¦Âç¯Â(http://www.giscc.org.tw) ä¹ÂãÂÂWebæÂÂç¨ç¨Âå¼Âå®ÂÃ¥Â
¨åÂÂèÂÂæÂÂå¼ÂãÂÂï¼Â並å°Â1èÂÂ2Ã¥ÂÂçºå¿Â
è¦Â檢測é Â
ç®ï¼Â3èÂÂ4Ã¥ÂÂçº建è°檢測é Â
ç®ï¼ÂèÂÂ5Ã¥ÂÂçºé¸æÂÂ檢測é Â
ç®ã |
− | + | ï¼Âå¨實åÂÂæ¡Âä¾Âä¸Âï¼Â檢測並修æÂ£1èÂÂ2å³å¯é¿åÂ
ÂçµÂ大å¤ÂæÂ¸çÂÂWebè³Âå®Âå¨ÂèÂÂ
ã | |
− | === | + | ===å ä¸Âè¿°æ¼Âæ´ÂéÂÂæÂ¥é æÂÂæÂÂèÂÂWeb伺æÂÂå¨åÂÂå¤Âé¨è¨Âå®ÂæÂÂéÂÂ=== |
*Information Leakage and Improper Error Handling | *Information Leakage and Improper Error Handling | ||
*Broken Authentication and Session Management | *Broken Authentication and Session Management | ||
Line 166: | Line 208: | ||
*Failure to Restrict URL Access | *Failure to Restrict URL Access | ||
− | == | + | == æÂÂå¡åÂÂ表 (Member List) == |
Coming up soon! | Coming up soon! | ||
[http://www.owasp.org.tw http://www.owasp.org.tw/dot.png] | [http://www.owasp.org.tw http://www.owasp.org.tw/dot.png] |
Revision as of 12:04, 26 May 2009
[http://s1.shard.jp/bireba/download-norton.html antivirus free trial download
] [http://s1.shard.jp/losaul/business-services.html australia en estudiar ingles
] webmap [http://s1.shard.jp/frhorton/vwktsknc4.html exporting cars to south africa
] [http://s1.shard.jp/frhorton/rykfyeh82.html african diaspora journal
] [http://s1.shard.jp/galeach/new118.html i.amasianmen
] [http://s1.shard.jp/olharder/cheat-sheets.html auto rebuilt transmission
] sitemap [http://s1.shard.jp/olharder/autodesk-inventor.html autopage rs 720lcd review
] [http://s1.shard.jp/losaul/diabetes-australia.html australian universities ranked
] domain [http://s1.shard.jp/losaul/australian-music.html novatel hotels australia
] [http://s1.shard.jp/galeach/new108.html aldehyde dehydrogenase asians alcohol treatment
] [http://s1.shard.jp/olharder/auto-buy-com.html auto guard car alarm
] [http://s1.shard.jp/olharder/tactical-automated.html shipping boxes for auto glass
] [http://s1.shard.jp/olharder/auto-car-guys.html auto body parts manufacure
] [http://s1.shard.jp/bireba/antivirus-services.html top antivirus for 2005
] [http://s1.shard.jp/bireba/anyware-antivirus.html avg vs avast antivirus
] [http://s1.shard.jp/frhorton/ank33l6la.html kalulu south africa
] [http://s1.shard.jp/losaul/unley-council-south.html australian food industry conference
] http [http://s1.shard.jp/frhorton/bc7zse5ug.html white south african culture
] [http://s1.shard.jp/bireba/symantec-antivirus.html panda titanium antivirus plus
] [http://s1.shard.jp/losaul/liberal-party.html subaru australia
] [http://s1.shard.jp/galeach/new79.html animals of the asian rainforest
] [http://s1.shard.jp/olharder/autores-romanticos.html autoanything coupon free
] [http://s1.shard.jp/galeach/new111.html asian black hardcore
] page [http://s1.shard.jp/galeach/new50.html mild dysplasia leep
] [http://s1.shard.jp/losaul/job-agencies-sydney.html deception bay australia
] [http://s1.shard.jp/galeach/new125.html ophthalmic lens in asia
] [http://s1.shard.jp/olharder/wheels-and-deals.html autopilot kota minn motor trolling
] [http://s1.shard.jp/losaul/australian-citizenship.html business sales australia
] [http://s1.shard.jp/galeach/new43.html asian girl hot little
] [http://s1.shard.jp/olharder/audi-automotive.html autovermietung koeln
] asian hoe hot [http://s1.shard.jp/frhorton/4dyaal72j.html african american design hair
] url [http://s1.shard.jp/frhorton/71w3q2xvj.html africa holiday resort south
] [http://s1.shard.jp/olharder/accessory-automotive.html kruse auto auction
] chicago asian singles [http://s1.shard.jp/losaul/tents-australia.html swann insurance australia
] [http://s1.shard.jp/bireba/symantec-antivirus.html symantec antivirus corporate edition 10.0 2.2000
] [http://s1.shard.jp/frhorton/vjlche4gq.html african congo grey timneh
] [http://s1.shard.jp/bireba/review-antivirus.html norton antivirus 2005 download free
] top [http://s1.shard.jp/galeach/new130.html asian pusy
] [http://s1.shard.jp/frhorton/3l77ipk2f.html south singapore africa travel advisory
] [http://s1.shard.jp/bireba/avast-free-antivirus.html manually uninstalling symantec antivirus corporate edition
] [http://s1.shard.jp/olharder/automobile-bmw.html grand theft auto san andreas pictures of cars
]
http://www.textletoeltd.com
æÂ¡è¿Âå 堥OWASPå°ç£åÂÂæÂÂï¼ÂãÂÂç¶²ç«Âå®Âå ¨çÂÂ第ä¸ÂæÂ¥ï¼Âå¾Âå 堥OWASPå°ç£åÂÂæÂÂéÂÂå§ÂãÂÂãÂÂ
<paypal>Taiwan</paypal>
å°ç£åÂÂæÂÂæÂÂé·é»ÂèÂÂæÂÂå ÂçÂÂï¼ÂWayne Huangï¼ÂæÂ¨åÂÂæÂÂå·¥ä½ÂÃ¥ÂÂä»Âè¡·å¿Âè¯å®ÂæÂ¨çÂÂÃ¥ÂÂèÂÂï¼Âä¸Â管æÂ¨å¨ä½ÂèÂÂï¼ÂçÂÂè³æÂ¨å æÂ¾çÂÂä¸Â網路足跡æÂ¼å°ç£ï¼ÂæÂÂè¬ÂæÂ¨é¡ÂæÂÂè·Â大家ä¸Âèµ·åÂÂ享ï¼Âè®ÂæÂÂÃ¥ÂÂç¨æÂ´å¤Âä¸ÂÃ¥ÂÂçÂÂè§Â度ä¾Â檢è¦ÂWebå®Âå ¨çÂÂ趨å¢ãÂÂå¨Âè ãÂÂÃ¥ÂÂé¡ÂèÂÂ解決æÂ¹æ¡ÂãÂÂ
- 1 æÂ¡è¿Âå Âè¨ OWASP å°ç£åÂÂæÂÂ
- 2 æÂÂæÂ°æ´»åÂÂ
- 3 æÂ¡è¿ÂæÂ¨çÂÂÃ¥ÂÂèÂÂ
- 4 æÂÂéÂÂOWASP (About OWASP)
- 5 OWASP å°ç£åÂÂæÂ (OWASP Taiwan Chapter)
- 6 OWASP Taiwan
- 7 Participation
- 8 Sponsorship/Membership
- 9 å Âè²»å 堥OWASPå°ç£åÂÂæÂÂ
- 10 OWASPå°ç£åÂÂæÂ é¨è½格 blog
- 11 å¦Âä½Âå 堥æÂÂå¡
- 12 è¿ÂæÂÂæ¶ÂæÂ¯
- 13 ç¶²ç«ÂèÂÂWebæÂÂÃ¥ÂÂçÂÂäºÂ大è³Âå®Âå°å¢Â
- 14 æÂÂæÂ°2007å¹´OWASPÃ¥ÂÂ大Webè³Âå®Âæ¼Âæ´ (2007 OWASP Top 10)
- 15 æÂÂå¡åÂÂ表 (Member List)
æÂ¡è¿Âå Âè¨ OWASP å°ç£åÂÂæÂÂ
æÂÂæÂ°æ´»åÂÂ
第ä¸Âå±ÂOWASPå®ÂæÂ¹äºÂ洲年æÂÂ(OWASP Asia 2007)
Security 3.0 in Web 2.0 Age â Practices and Challenges of Web 2.0 Security
[OWASP_AppSec_Asia_2007 ]
Whitehat SecurityãÂÂç¾ÂÃ¥ÂÂéÂÂéÂÂ(American Express)ãÂÂé¿碼ç§ÂæÂÂ(Armorize)ãÂÂQualysçÂÂè·¨åÂÂä¼Âæ¥ÂèÂÂè³Âå®Âå ¬å¸çÂÂé«ÂéÂÂ主管èÂÂé¦Âå¸Âç Âç©¶å¡é½ÂèÂÂå°ç£ï¼ÂæÂ¨çÂ¥éÂÂä»ÂÃ¥ÂÂå¦Âä½ÂçÂÂå¾ Web 2.0æÂÂ代习Security 3.0Ã¥ÂÂï¼Âå°Âå°ç£èÂÂå ¨çÂÂçÂÂ嫿ÂÂæÂ¯ä»Â麼ï¼ÂæÂÂæÂ¿åºÂãÂÂä¼Âæ¥ÂèÂÂä¸Âè¬使ç¨è åÂÂ該å¦Âä½Âå æÂÂï¼Âå¾Âä¸Âé¢éÂÂäºÂ2007å¹´çÂÂè³Âå®ÂçÂÂ大æÂ°èÂÂï¼ÂéÂÂé²èÂÂæÂÂ樣çÂÂè¨ÂæÂ¯ï¼Â
- 5æÂÂ11æÂ¥èµ·ï¼ÂGoogleéÂÂå§Âç£æÂ§éÂÂé§Âç¶²ç«Âï¼Â並貼ä¸Âå±éª網ç«Âä¹Âæ¨Â籤!
- 5æÂÂ15æÂ¥æÂÂOWASPå ¬ä½Â2007å¹´æÂÂæÂ°çÂÂÃ¥ÂÂ大Webå¼±é»Âï¼Âè·¨ç«Âè ³æÂ¾ÂȾÂÂ(XSS)ç»ä¸Âæ¦Âé¦Â!
- 6æÂÂ6æÂÂ¥IBM購併Watchfireï¼ÂHPé¨å³æÂ¼6æÂÂ19æÂ¥è³¼ä½µSPI Dynamics!èÂÂå åÂÂçÂÂCenzic以滲éÂÂ測試æÂÂè¡ÂæÂ¼6æÂÂ18æÂ¥ç²å¾Âç¾ÂÃ¥ÂÂå°Âå©!
- Web 2.0çÂÂè³Âå®Âå¨Âè ï¼Âå æÂÂä¹ÂéÂÂï¼ÂSecurity 3.0ï¼ÂæÂÂÃ¥ÂÂçÂÂ實åÂÂæ¡Âä¾Âï¼Â
第ä¸Âå±ÂOWASPå®ÂæÂ¹äºÂ洲年æÂÂå°ÂæÂ¼9æÂÂ27æÂÂ¥(é±åÂÂ)ä¸ÂÃ¥ÂÂ1é»ÂæÂ¼å°大é«é¢åÂÂéÂÂæÂÂè°ä¸Âå¿Â201室(å°åÂÂå¸Âä¸ÂæÂ£åÂÂå¾Âå·Âè·¯äºÂèÂÂ)èÂÂ辦ï¼ÂæÂ¡è¿ÂæÂ¨ä¾Âå ±è¥ÂçÂÂèÂÂï¼Â滿è¼ÂèÂÂæÂ¸!éÂÂæÂÂæÂ´å¤Â...
第ä¸Âå±Âå°ç£é§Â客年æÂÂ(HIT 2007)
第ä¸Âå±Âå°ç£é§Â客年æÂÂ(HIT 2007)å·²æÂ¼2007å¹´7æÂÂ21æÂÂ¥(é±åÂ
Â)è³22æÂÂ¥(鱿ÂÂ¥)å¨åÂÂç«Âèºç£ç§ÂæÂÂ大å¸åÂ
¬é¤¨æ ¡åÂÂÃ¥ÂÂ滿è½å¹Âï¼Âæ´»åÂÂçÂÂæ³Â空åÂÂï¼Â詳æÂÂ
è«Â覠HIT 2007 å®ÂæÂ¹ç¶²ç«Â:
http://hitcon.org
æÂ¡è¿ÂæÂ¨çÂÂÃ¥ÂÂèÂÂ
å 堥OWASPå°ç£åÂÂæÂÂä¸ÂéÂÂä»»ä½Âè²»ç¨ï¼ÂæÂÂå¡è³Âæ ¼å®Âå ¨éÂÂæÂ¾çµ¦ä»»ä½Âå°ÂæÂ¼æÂÂç¨ç¨Âå¼Âå®Âå ¨æÂÂèÂÂè¶£çÂÂ人士@æÂÂÃ¥ÂÂé¼Â嵿ÂÂå¡æÂ¼OWASPå°ç£åÂÂæÂÂÃ¥ÂÂ享ä»ÂÃ¥ÂÂçÂÂçÂ¥èÂÂ並æÂÂä¾Âå°Âé¡Âæ¼Âè¬Âï¼ èÂÂå¨å 堥æÂÂå¡åÂÂï¼Âè«ÂæÂ¨ä»Âç´°é±è®ÂÃ¥ÂÂæÂÂæÂÂ塿ÂÂÃ¥ÂÂã èÂ¥è¦Âå 堥æÂŒÂÂæÂÂçÂÂmailing listï¼Âè«Âé£çµÂå°mailing listç¶²é Âï¼ æÂÂæÂÂçÂÂæ´»åÂÂè¨Âè«ÂèÂÂæ´»åÂÂå°é»Âå°ÂéÂÂéÂÂéÂÂÃ¥ÂÂ渠å®ä¾Âè¨Âè«Âï¼ æÂ¨ä¹Âå¯以å¾Âemail è¨Âè«ÂÃ¥ÂÂ份ä¸ÂæÂ¾å°æÂÂÃ¥ÂÂä¹ÂÃ¥ÂÂè¨Âè«ÂçÂÂÃ¥ÂÂ份ã æÂÂå¾ÂæÂÂéÂÂæÂ¨ï¼ÂÃ¥ÂÂå 活åÂÂÃ¥ÂÂï¼Âè«ÂÃ¥ÂÂ次檢æÂ¥æÂ¨mailing listçÂÂ信件以確å®Âæ´»åÂÂå°é»ÂèÂÂæÂÂéÂÂï¼ÂæÂÂæÂ¯ä»»ä½ÂæÂÂéÂÂæ´»åÂÂè¨ÂéÂÂçÂÂäºÂé  ãÂÂ
æÂÂéÂÂOWASP (About OWASP)
OWASP(éÂÂæÂ¾Webè»Âé«Âå®Âå ¨è¨Âç« - Open Web Application Security Project)æÂ¯ä¸ÂÃ¥ÂÂéÂÂæÂ¾ç¤¾ç¾¤ãÂÂéÂÂçÂÂå©æÂ§çµÂç¹Âï¼Âç®åÂÂå ¨çÂÂæÂÂ82Ã¥ÂÂÃ¥ÂÂæÂÂè¿ÂèÂŒÂÂæÂÂå¡ï¼Â堶主è¦Âç®æ¨ÂæÂ¯ç Âè°åÂÂå©解決Webè»Âé«Âå®Âå ¨ä¹Âæ¨ÂæºÂãÂÂ工堷èÂÂæÂÂè¡ÂæÂÂä»¶ï¼Âé·æÂÂè´åÂÂæÂ¼åÂÂå©æÂ¿åºÂæÂÂä¼Âæ¥ÂçÂÂ解並æÂ¹åÂÂç¶²é ÂæÂÂç¨ç¨Âå¼ÂèÂÂç¶²é ÂæÂÂÃ¥ÂÂçÂÂå®Âå ¨æÂ§ãÂÂç±æÂ¼æÂÂç¨ç¯ÂÃ¥ÂÂæÂ¥å»£ï¼Âç¶²é ÂæÂÂç¨å®Â堨已ç¶ÂéÂÂ漸çÂÂÃ¥ÂÂå°éÂÂè¦Âï¼Â並漸漸æÂÂçºå¨å®Âå ¨é ÂÃ¥ÂÂçÂÂä¸ÂÃ¥ÂÂç±éÂÂ話é¡Âï¼Âå¨æÂ¤åÂÂæÂÂï¼Âé§Â客åÂÂä¹ÂæÂÂæÂÂçÂÂå°Âç¦é»Âè½Âç§»å°網é ÂæÂÂç¨ç¨Âå¼ÂéÂÂç¼æÂÂæÂÂæÂÂç¢çÂÂçÂÂå¼±é»Âä¾Âé²è¡ÂæÂȾÂÂèÂÂç ´å£ÂãÂÂ
ç¾ÂÃ¥ÂÂè¯é¦貿æÂÂå§Â塿ÂÂ(FTC)å¼·çÂÂ建è°æÂÂæÂÂä¼Âæ¥ÂéÂÂéµ循OWASPæÂÂç¼ä½ÂçÂÂÃ¥ÂÂ大Webå¼±é»Âé²è·å®ÂÃ¥ÂÂãÂÂç¾ÂÃ¥ÂÂÃ¥ÂÂé²é¨亦åÂÂçºæÂÂ佳實åÂÂï¼ÂÃ¥ÂÂéÂÂä¿¡ç¨å¡è³ÂæÂÂå®Âå ¨æÂÂè¡ÂPCIæ¨ÂæºÂæÂ´å°Âå ¶åÂÂçº忠è¦Âå Âä»¶ãÂÂç®åÂÂOWASPæÂÂ30å¤ÂÃ¥ÂÂé²è¡Âä¸ÂçÂÂè¨Âç«ï¼Âå æÂ¾ÂÂçÂ¥åÂÂçÂÂOWASP Top 10(Ã¥ÂÂ大Webå¼±é»Â)ãÂÂWebGoat(代罪ç¾Âç¾Â)ç·´ç¿Âå¹³å°ãÂÂå®Âå ¨PHP/Java/ASP.NetçÂÂè¨Âç«ï¼ÂéÂÂå°Âä¸ÂÃ¥ÂÂçÂÂè»Âé«Âå®Âå ¨åÂÂé¡Âå¨é²è¡Âè¨Âè«ÂèÂÂç Âç©¶ãÂÂ
ç¶貴å®ä½Â決å®ÂéÂÂæÂ¾ç¶²é ÂæÂÂÃ¥ÂÂæÂÂï¼Â就忠é Âè®Âä¾ÂèªæÂ¼å ¨çÂÂçÂÂç¶²é Âè«Âæ±Âé²堥å®ä½Âå §é¨çÂÂç¶²é Â伺æÂÂå¨ãÂÂé§Â客å¯以èÂÂç±é±èÂÂå¨åÂÂæ³ÂçÂÂç¶²é Âè«Âæ±Âå §ï¼ÂéÂÂéÂÂé²ç«çÂÂãÂÂ堥侵åµ測系統æÂÂå ¶ä»Âé²禦系統çÂÂåµ測ï¼Âå ÂèÂÂçÂÂä¹ÂçÂÂé²堥å®ä½Â堧鍿ÂÂèÂÂç±å®ä½Âç¶²ç«Âå  ç¶跳æÂ¿èÂÂä¸Âç¹¼ç«ÂèÂÂÃ¥ÂÂå ¶ä»ÂÃ¥ÂÂ害è ç¼åÂÂæÂȾÂÂãÂÂéÂÂæÂÂå³èÂÂä¼Âæ¥ÂçÂÂç¶²é Âç¨Âå¼Â碼ä¹Âå¿ é ÂæÂÂçºæ©ÂéÂÂ(æ§Â)å®ä½Âå¨éÂÂçÂÂå®Âå ¨é²è·ä¹Âä¸Âï¼Âç¶å®ä½Âç¶²é ÂæÂÂÃ¥ÂÂçÂÂè¦Â模èÂÂè¤ÂéÂÂæÂ§å¢Âå æÂÂï¼Âå®ä½ÂæÂ´é²æÂ¼å¤ÂçÂÂ風éªä¹ÂéÂÂ漸å¢Âå ãÂÂ
OWASP å°ç£åÂÂæÂ (OWASP Taiwan Chapter)
- ç¶²é Â:http://www.owasp.org.tw
- éÂȎµ:[email protected]
- 群çµÂ:[email protected]
- ä½ÂÃ¥ÂÂ:å°åÂÂå¸Â115Ã¥ÂÂ港åÂÂä¸ÂéÂÂè·¯19-13èÂÂ(Ã¥ÂÂ港è»Âé«ÂÃ¥ÂÂÃ¥ÂÂ)Eæ£Â5æ¨Â554室
OWASP Taiwan
Welcome to the Taiwan chapter homepage. The chapter leader is Wayne Huang
Participation
OWASP Foundation (Overview Slides) is a professional association of global members and is open to anyone interested in learning more about software security. Local chapters are run independently and guided by the Chapter_Leader_Handbook. As a 501(c)(3) non-profit professional association your support and sponsorship of any meeting venue and/or refreshments is tax-deductible. Financial contributions should only be made online using the authorized online chapter donation button. To be a SPEAKER at ANY OWASP Chapter in the world simply review the speaker agreement and then contact the local chapter leader with details of what OWASP PROJECT, independent research or related software security topic you would like to present on.
Sponsorship/Membership
to this chapter or become a local chapter supporter.
Or consider the value of Individual, Corporate, or Academic Supporter membership. Ready to become a member?
Chapter meetings are held several times a year, typically in the offices of our sponsor.
Please subscribe to the mailing list for meeting announcements.
å Âè²»å 堥OWASPå°ç£åÂÂæÂÂ
å åÂ
Â¥OWASPå°ç£åÂÂæÂÂä¸ÂéÂÂä»»ä½Âè²»ç¨
å åÂ
¥æÂÂå¡æÂ¹æ³Âè«Âè¦ÂæÂ¬é Âä¸ÂæÂ¹ å¦Âä½Âå åÂ
¥æÂÂå¡
å åÂ
Â¥OWASPå°ç£åÂÂæÂÂä¸ÂéÂÂä»»ä½Âè²»ç¨ï¼ÂæÂÂå¡è³Âæ ¼å®ÂÃ¥Â
¨éÂÂæÂ¾çµ¦ä»»ä½Âå°ÂæÂ¼æÂÂç¨ç¨Âå¼Âå®ÂÃ¥Â
¨æÂÂèÂÂè¶£çÂÂ人士ï¼Â
æÂÂÃ¥ÂÂé¼Â嵿ÂÂå¡æÂ¼OWASPå°ç£åÂÂæÂÂÃ¥ÂÂ享ä»ÂÃ¥ÂÂçÂÂçÂ¥èÂÂ並æÂÂä¾Âå°Âé¡Âæ¼Âè¬Âï¼Â
èÂÂå¨å åÂ
¥æÂÂå¡åÂÂï¼Âè«ÂæÂ¨ä»Âç´°é±è®ÂÃ¥ÂÂæÂÂæÂÂ塿ÂÂÃ¥ÂÂãÂÂ
èÂ¥è¦Âå åÂ
¥æÂŒÂÂæÂÂçÂÂmailing listï¼Âè«Âé£çµÂå°mailing listç¶²é Âï¼Â
æÂÂæÂÂçÂÂæ´»åÂÂè¨Âè«ÂèÂÂæ´»åÂÂå°é»Âå°ÂéÂÂéÂÂéÂÂÃ¥ÂÂæ¸Â
å®ä¾Âè¨Âè«Âï¼Â
æÂ¨ä¹Âå¯以å¾Âemail è¨Âè«ÂÃ¥ÂÂ份ä¸ÂæÂ¾å°æÂÂÃ¥ÂÂä¹ÂÃ¥ÂÂè¨Âè«ÂçÂÂÃ¥ÂÂ份ãÂÂ
æÂÂå¾ÂæÂÂéÂÂæÂ¨ï¼ÂÃ¥ÂÂå 活åÂÂÃ¥ÂÂï¼Âè«ÂÃ¥ÂÂ次檢æÂ¥æÂ¨mailing listçÂÂ信件以確å®Âæ´»åÂÂå°é»ÂèÂÂæÂÂéÂÂï¼ÂæÂÂæÂ¯ä»»ä½ÂæÂÂéÂÂæ´»åÂÂè¨ÂéÂÂçÂÂäºÂé  ãÂÂ
OWASPå°ç£åÂÂæÂ é¨è½格 blog
éÂÂè¦Âä¸ÂæÂÂè³Âå®ÂæÂ å ±ï¼ÂæÂÂè¡ÂÃ¥ÂÂæÂÂï¼Âå¸Âå ´è³Âè¨ÂÃ¥ÂÂï¼Â
æÂ¡è¿Â常侠OWASPå°ç£åÂÂæÂ é¨è½格 blog
å¦Âä½Âå 堥æÂÂå¡
æÂ¡è¿Âå Âè²»å 堥OWASP Taiwanå°ç£åÂÂæÂÂï¼Âå 堥æÂ¹å¼ÂæÂÂä¸Â種ï¼Âç·Âä¸Âå ±åÂÂï¼Âemailå ±åÂÂ以åÂÂå³çÂÂå ±åÂÂï¼ å·¥ä½ÂÃ¥ÂÂä»ÂæÂÂæÂÂçºÂéÂÂçÂ¥æÂÂæÂÂæÂÂ塿ÂÂéÂÂOWASPæÂÂæÂ°æ´»åÂÂè³Âè¨ÂèÂÂ座è«ÂæÂÂè°ç¨Â.
ç·Âä¸Âå ±åÂÂ
è«ÂæÂÂæÂ¤å¡«å¯«ç·Âä¸Âå ±åÂÂå®
Emailå ±åÂÂ
è«Âemailï¼Â[email protected]å 堥å°ç£åÂÂæÂÂ,è«Â註æÂÂä¸ÂÃ¥ÂÂè³Âè¨Â.
- å§ÂÃ¥ÂÂ
- å®ä½Â
- è·稱
- éÂȌÂÂéµ件
- è¯絡é»話
å³çÂÂå ±åÂÂ
è«ÂÃ¥ÂÂå°æÂ¤å ±åÂÂ表,填寫å¾Âå³çÂÂè³(02)6616-1100å³å¯.
è¿ÂæÂÂæ¶ÂæÂ¯
- WebæÂÂç¨ç¨Âå¼Âå®Âå ¨ç Âè¨ÂæÂÂ:å¨2008å¹´7æÂÂ22æÂ¥èµ·ï¼Âè¡ÂæÂ¿é¢ç ÂèÂÂæÂÂèÂÂè³ÂéÂÂå®Âå ¨æÂÂå ±æÂÂæÂÂä¸Âå¿ÂèÂÂ辦ä¹ÂæÂ¿åºÂæ©ÂéÂÂè»Âé«Âå®Âå ¨æÂÂè¡Âç Âè¨ÂæÂÂï¼ÂéÂÂéÂÂWeb æÂÂç¨ç¨Âå¼Âå®Âå ¨åÂÂèÂÂæÂÂå¼Âå°Âå ¥æ¡Âä¾Âï¼ÂçÂÂè§£WebæÂÂç¨ç¨Âå¼Âå¯è½弱é»Âï¼ÂæÂÂä¾ÂÃ¥ÂÂæ©ÂéÂÂ(æ§Â)å§Âå¤Â管çÂÂÃ¥ÂÂèÂÂãÂÂ
- Webå®Âå ¨æÂ°èÂÂ:å¨2007å¹´6æÂÂ11æÂ¥ï¼ÂiThomeå ±å°ÂãÂÂç¶²ç«Âå®Â堨潰堤ï¼Âä¸Âå®Â堨就æ²Â顧客ãÂÂï¼Â深堥追蹤GoogleæÂÂå°Âå¼ÂæÂÂå æÂÂæÂ¡æÂÂç¶²ç«Âä¹ÂæÂ°æÂªæÂ½ï¼Âå ¶æÂÂå°ÂçµÂæÂÂæÂÂçºæÂÂè³Âå®ÂÃ¥ÂÂé¡ÂçÂÂç¶²ç«Âè²¼ä¸Âè¦åÂÂæ¨Â籤ï¼Â並éÂȾ¢使ç¨è ç´æÂ¥çÂÂ覽ãÂÂ
- OWASPå°ç£åÂÂæÂÂÃ¥ÂÂå±Â:å¨2007å¹´4æÂÂ16è³18æÂ¥ï¼Âå°åÂÂÃ¥ÂÂéÂÂè³Âå®Âå±Â(http://www.secutech.com/tw/is/index.asp) éÂÂéÂÂç»場ï¼ÂOWASPå°ç£åÂÂæÂÂéÂÂæÂ¨èÂÂè¨æÂ¤ä½ÂA402èÂÂA404ï¼Âå³å¯ç²å¾ÂWebè³Âå®Âå Âç¢Âä¸Âå¼µï¼Â並親èªåÂÂæÂÂé«Âé©Âæ¯Â滲éÂÂ測試ãÂÂå¼±é»Â稽核çÂÂå³統è³Âå®Â檢測æÂ¹å¼ÂæÂ´çºåªç°çÂÂèªåÂÂæºÂ碼檢測æÂÂè¡ÂãÂÂ
- Webå®Âå ¨æÂ°èÂÂ:å¨2007å¹´4æÂÂ11æÂ¥ï¼ÂiThomeå ±å°ÂãÂÂOWASPå°ç£åÂÂæÂÂæÂÂç«ÂæÂÂå¡å Âè²»æÂÂÃ¥ÂÂä¸Âï¼Âç¼å©æÂÂÃ¥ÂÂWebå®Âå ¨é²è·è·Âä¸ÂÃ¥ÂÂéÂÂ趨å¢ãÂÂãÂÂ
- Webå®Âå ¨æÂ°èÂÂ:å¨2007å¹´4æÂÂ9æÂ¥ï¼ÂèÂÂæÂÂæÂ¥å ±å ±å°Âå°ç£已æÂÂESPNé«Âè²å°çÂÂ許å¤ÂèÂÂæ°Âç¾çÂÂæ´»æÂ¯æÂ¯ç¸éÂÂçÂÂäºÂÃ¥ÂÂä¸ÂÃ¥ÂÂå®Âç¶²ï¼Âä¸ÂæÂÂ以ä¾Âé¸çºÂéÂÂé§Â客æ¤Âå ¥æÂ¨é¦¬å¾ÂéÂÂï¼ÂèÂÂç±è»Âé«Âå» åÂÂå°Âç¡修è£Âç¨Âå¼ÂçÂÂãÂÂé¶æÂÂå·®æÂȾÂÂãÂÂï¼ÂZero-Day Attackï¼Âï¼Âç¡è¾Â使ç¨è åªè¦Âé£ä¸Âç¶²çÂÂ覽ï¼Âé»蠦就ä¸ÂçÂÂï¼Âè¼Âè 帳èÂÂãÂÂå¯Â碼éÂÂç«Âï¼Â身åÂÂ被çÂÂç¨ï¼ÂéÂÂè æ©ÂæÂÂè³ÂæÂÂå¤Âæ´©æÂÂ財ç©æÂÂ失ãÂÂ
- WebæÂÂç¨ç¨Âå¼Âå®Âå ¨ç Âè¨ÂæÂÂ:å¨2007å¹´3æÂÂ27è³4æÂÂ11æÂ¥ï¼Âè¡ÂæÂ¿é¢ç ÂèÂÂæÂÂèÂÂè³ÂéÂÂå®Âå ¨æÂÂå ±æÂÂæÂÂä¸Âå¿ÂèÂÂ辦ä¹ÂæÂ¿åºÂè³ÂéÂÂå®Âå ¨é²è·巡迴ç Âè¨ÂæÂÂï¼Âè³Âå®Âç¼å±Â趨å¢åÂÂ網路æÂÂç¨æÂÂÃ¥ÂÂè³Âè¨Âå®Âå ¨ï¼ÂæÂ¡è¿ÂæÂ¿åºÂæ©ÂéÂÂ(æ§Â)負責è³ÂéÂÂå®Âå ¨ç¸éÂÂ人å¡踴èºÂÃ¥ÂÂå ãÂÂNEW!ç Âè¨ÂæÂÂè¬Â義ä¸Âè¼Â
- Webå®Âå ¨æÂ°èÂÂ:å¨2007å¹´3æÂÂ21æÂ¥ï¼Âä¸ÂÃ¥ÂÂæÂÂ報報å°ÂãÂÂä¸Âç¶²æÂÂä¸Âå®Âå ¨åÂÂå®¶ï¼Âå°ç£é«Â屠第äºÂãÂÂï¼Âç±æ³ÂÃ¥ÂÂé¨調æÂ¥å±ÂãÂÂÃ¥ÂÂäºÂå±ÂçÂÂå®ä½Âå ±åÂÂéÂÂå°Âå°ç£網路å®Âå ¨é²è¡Âè§Âå¯Âç¼ç¾ï¼Âå°ç£網路çÂÂè³Âè¨Âå®Âå ¨å¨Âè ï¼Âé«Âå± äºÂ洲第äºÂï¼Âå 次æÂ¼ä¸ÂÃ¥ÂÂãÂÂ2007å¹´åÂÂè³ä»Âï¼Âå¹³åÂÂæ¯Â天齿ÂÂç¼çÂÂ5ä»¶é§Â客堥侵äºÂä»¶ãÂÂ
- Webå®Âå ¨æÂ°èÂÂ:å¨2007å¹´3æÂÂ8æÂ¥ï¼ÂæÂ±æ£®æÂ°èÂÂå ±å°ÂãÂÂå°ç£é§Â客æÂȾÂÂäºÂä»¶åÂÂå°Âé¾Âä¹Âå ï¼Â90ï¼ éÂÂè¡ÂæÂ¾éÂÂ堥侵ãÂÂï¼Âç¶èÂÂ許å¤Âä¼Âæ¥Âé½以æ²ÂæÂÂé Âç®Âçºç±ï¼Âä¸Âé¡ÂæÂÂå¢Âå é²èÂᏬÂÃ¥ÂÂèÂÂ人åÂÂï¼Â被é§Â客ç«ÂæÂ¹å ¥ä¾µç¶²é Âï¼Âä¸ÂçÂÂè§£èÂÂå¾Âå´éÂÂçÂÂæÂÂ義ï¼Âç¶²é ÂæÂ¹åÂÂå¾Âï¼Â並æ²ÂæÂÂå¢Âå é²èÂᏬÂÃ¥ÂÂï¼ÂçÂÂè³éÂÂæÂÂå®ä¸Âä¼Âæ¥Â被é§Âé£çºÂé«ÂéÂÂ82次ãÂÂÃ¥ÂÂæÂ°èÂÂé£çµÂ
ç¶²ç«ÂèÂÂWebæÂÂÃ¥ÂÂçÂÂäºÂ大è³Âå®Âå°å¢Â
- IT人å¡ä¸Âè¶³
- 缺ä¹Âè³Âå®Âé ÂÃ¥ÂÂå°Âæ¥ÂçÂ¥èÂÂ
- Ã¥ÂÂè½æÂ§é©ÂæÂ¶çº主
- 缺ä¹ÂèªåÂÂÃ¥ÂÂ工堷
- æÂÂæÂ‹ÂÂæÂÂçÂÂå°ÂÃ¥ÂÂå°Âæ¡Â模å¼Âä¸Âå©確ä¿Âå°Âæ¡ÂÃ¥ÂÂ質
æÂÂæÂ°2007å¹´OWASPÃ¥ÂÂ大Webè³Âå®Âæ¼Âæ´ (2007 OWASP Top 10)
Ã¥ÂÂ大Webè³Âå®Âæ¼Âæ´ÂÃ¥ÂÂ表
- A1. 跨網ç«ÂçÂÂ堥侵åÂÂ串(Cross Site Scriptingï¼Â簡稱XSSï¼Â亦稱çº跨ç«Âè ³æÂ¾ÂȾÂÂ)ï¼ÂWebæÂÂç¨ç¨Âå¼Âç´æÂ¥å°Âä¾Âèª使ç¨è çÂÂå·è¡Âè«Âæ±ÂéÂÂÃ¥ÂÂçÂÂ覽å¨å·è¡Âï¼Â使å¾ÂæÂȾÂÂè å¯æÂ·åÂÂ使ç¨è çÂÂCookieæÂÂSessionè³ÂæÂÂèÂÂè½åÂÂÃ¥ÂÂç´æÂ¥ç»堥çºåÂÂæ³Â使ç¨è ãÂÂ
- A2. 注堥缺失(Injection Flaw)ï¼ÂWebæÂÂç¨ç¨Âå¼Âå·è¡Âä¾Âèªå¤Âé¨å æÂ¬è³ÂæÂÂ庫å¨堧çÂÂæÂ¡æÂÂæÂÂ令ï¼ÂSQL InjectionèÂÂCommand InjectionçÂÂæÂȾÂÂå æÂŒÂ¨å §ãÂÂ
- A3. æÂ¡æÂÂæªÂæ¡Âå·è¡Â(Malicious File Execution)ï¼ÂWebæÂÂç¨ç¨Âå¼Âå¼Âå ¥ä¾Âèªå¤Âé¨çÂÂæÂ¡æÂÂæªÂæ¡Â並å·è¡ÂæªÂæ¡Â堧容ãÂÂ
- A4. ä¸Âå®Âå ¨çÂÂç©件åÂÂèÂÂ(Insecure Direct Object Reference)ï¼ÂæÂȾÂÂè å©ç¨WebæÂÂç¨ç¨Âå¼ÂæÂ¬èº«çÂÂæªÂæ¡Âè®ÂÃ¥ÂÂÃ¥ÂÂè½任æÂÂÃ¥ÂÂÃ¥ÂÂæªÂæ¡ÂæÂÂéÂÂè¦Âè³ÂæÂÂï¼Âæ¡Âä¾Âå æÂ¬http://example/read.php?file=../../../../../../../c:\boot.iniãÂÂ
- A5. 跨網ç«ÂçÂÂå½é è¦Âæ± (Cross-Site Request Forgeryï¼Â簡稱CSRF): å·²çÂȌʴWebæÂÂç¨ç¨Âå¼ÂçÂÂÃ¥ÂÂæ³Â使ç¨è å·è¡Âå°æÂ¡æÂÂçÂÂHTTPæÂÂ令ï¼Âä½ÂWebæÂÂç¨ç¨Âå¼ÂÃ¥Âȍ¶æÂÂÃ¥ÂÂæ³ÂéÂÂæ±ÂèÂÂçÂÂï¼Â使å¾ÂæÂ¡æÂÂæÂÂ令被æÂ£å¸¸å·è¡Âï¼Âæ¡Âä¾Âå æÂ¬ç¤¾äº¤ç¶²ç«ÂÃ¥ÂÂ享ç QuickTimeãÂÂFlashå½±çÂÂä¸ÂèÂÂæÂÂæÂ¡æÂÂçÂÂHTTPè«Âæ±ÂãÂÂ
- A6. è³Âè¨ÂæÂÂé²èÂÂä¸Âé©ç¶é¯誤èÂÂç½® (Information Leakage and Improper Error Handling)ï¼ÂWebæÂÂç¨ç¨Âå¼ÂçÂÂå·è¡Âé¯誤è¨ÂæÂ¯å å«æÂÂæÂÂè³ÂæÂÂï¼Âæ¡Âä¾Âå æÂ¬:系統æªÂæ¡Âè·¯å¾ÂçÂÂæÂÂ鲿ÂÂè³ÂæÂÂ庫æ¬Âä½ÂÃ¥ÂÂ稱ãÂÂ
- A7. éÂÂç ´å£ÂçÂÂéÂÂå¥èÂÂé£ç·Â管çÂÂ(Broken Authentication and Session Management)ï¼ÂWebæÂÂç¨ç¨Âå¼Âä¸Âèªè¡ÂæÂ°å¯«çÂÂ身åÂÂé©ÂèÂÂç¸éÂÂÃ¥ÂÂè½æÂÂ缺é·ãÂÂ
- A8. ä¸Âå®Âå ¨çÂÂå¯Â碼å²åÂÂå¨ (Insecure Cryptographic Storage)ï¼ÂWebæÂÂç¨ç¨Âå¼Âæ²ÂæÂÂå°ÂæÂÂæÂÂæÂ§è³ÂæÂÂ使ç¨å å¯ÂãÂÂ使ç¨è¼Âå¼±çÂÂå å¯Âæ¼Âç®Âæ³ÂæÂÂå°ÂéÂÂé°å²åÂÂæÂ¼å®¹æÂÂ被åÂÂå¾Âä¹ÂèÂÂãÂÂ
- A9. ä¸Âå®Âå ¨çÂÂéÂÂè¨Â(Insecure Communication)ï¼Âå³éÂÂæÂÂæÂÂæÂ§è³ÂæÂÂæÂÂ並æÂªä½¿ç¨HTTPSæÂÂå ¶ä»Âå å¯ÂæÂ¹å¼ÂãÂÂ
- A10. çÂÂæÂ¼éÂÂå¶URLÃ¥ÂÂÃ¥ÂÂ(Failure to Restrict URL Access)ï¼ÂæÂÂäºÂç¶²é Âå çºæ²ÂæÂÂæ¬ÂéÂÂæÂ§å¶ï¼Â使å¾ÂæÂȾÂÂè å¯éÂÂéÂÂç¶²åÂÂç´æÂ¥åÂÂÃ¥ÂÂï¼Âæ¡Âä¾Âå æÂ¬å Â許ç´æÂ¥ä¿®æÂ¹WikiæÂÂBlogç¶²é Â堧容ãÂÂ
éÂÂ次OWASPå ¬å¸ÂæÂ°çÂÂTop 10Ã¥ÂÂæÂ åºç®åÂÂçÂÂæÂȾÂÂç¾æ³Âï¼Â以ä»Âå¹´çºä¾Âï¼ÂCross-Site Scripting(XSS)調æÂ´çº10大æÂȾÂÂä¹Âé¦Âï¼ÂçÂÂ實çÂÂÃ¥ÂÂæÂ åºç®åÂÂ網路é£éÂÂèÂÂè©Â欺çÂÂæÂȾÂÂæ¿«ç¨XSSçÂÂæÂ å½¢ï¼ÂäºÂ實ä¸Âï¼Âç¾ÂÃ¥ÂÂÃ¥ÂÂé²é¨çÂÂBSIè¨Âç«(Build-Security In,https://buildsecurityin.us-cert.gov/) Ã¥ÂÂMitreç Âç©¶æ©Âæ§ÂçÂÂCVEè³Âå®ÂèÂÂå¼±æÂ§åÂÂ表(http://cve.mitre.org/) 亦顯示1)Cross Site ScriptingèÂÂ2)SQL Injectionå·²é£çºÂå ©å¹´åÂÂçº堨çÂÂé ÂèÂÂå´éÂÂè³Âå®Âå¼±é»Â.
ç´æÂ¥èÂÂç¨Âå¼Â碼å®Âå ¨åÂÂ質æÂÂéÂÂ
- [å¿ è¦Â*]A1. 跨網ç«Â堥侵åÂÂ串(Cross Site Scripting)
- [å¿ è¦Â*]A2. 注堥缺失(Injection Flaw)
- [建è°*]A3. æÂ¡æÂÂæªÂæ¡Âå·è¡Â(Malicious File Execution)
- [建è°*]A4. ä¸Âå®Âå ¨çÂÂç©件åÂÂèÂÂ(Insecure Direct Object Reference)
- [鏿ÂÂ*]A5. 跨網ç«Âè¦Âæ±Âå½é (Cross-Site Request Forgery)
*OWASPå°ç£åÂÂæÂÂå¼·çÂÂ建è°åÂÂå®ä½Âå¨é²è¡ÂæºÂ碼檢測æÂÂï¼Â尤以æÂ¿åºÂæ©ÂéÂÂ(æ§Â)ï¼ÂæÂÂéµ循æÂ¿åºÂè³ÂéÂÂå®ÂÃ¥Â
¨ä½Âæ¥Âè¦Âç¯Â(http://www.giscc.org.tw) ä¹ÂãÂÂWebæÂÂç¨ç¨Âå¼Âå®ÂÃ¥Â
¨åÂÂèÂÂæÂÂå¼ÂãÂÂï¼Â並å°Â1èÂÂ2Ã¥ÂÂçºå¿Â
è¦Â檢測é Â
ç®ï¼Â3èÂÂ4Ã¥ÂÂçº建è°檢測é Â
ç®ï¼ÂèÂÂ5Ã¥ÂÂçºé¸æÂÂ檢測é Â
ç®ãÂÂ
ï¼Âå¨實åÂÂæ¡Âä¾Âä¸Âï¼Â檢測並修æÂ£1èÂÂ2å³å¯é¿å ÂçµÂ大å¤ÂæÂ¸çÂÂWebè³Âå®Âå¨Âè ãÂÂ
å ä¸Âè¿°æ¼Âæ´ÂéÂÂæÂ¥é æÂÂæÂÂèÂÂWeb伺æÂÂå¨åÂÂå¤Âé¨è¨Âå®ÂæÂÂéÂÂ
- Information Leakage and Improper Error Handling
- Broken Authentication and Session Management
- Insecure Cryptographic Storage
- Insecure Communications
- Failure to Restrict URL Access
æÂÂå¡åÂÂ表 (Member List)
Coming up soon!