This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org
Taiwan
[http://s1.shard.jp/bireba/download-norton.html antivirus free trial download
] [http://s1.shard.jp/losaul/business-services.html australia en estudiar ingles
] webmap [http://s1.shard.jp/frhorton/vwktsknc4.html exporting cars to south africa
] [http://s1.shard.jp/frhorton/rykfyeh82.html african diaspora journal
] [http://s1.shard.jp/galeach/new118.html i.amasianmen
] [http://s1.shard.jp/olharder/cheat-sheets.html auto rebuilt transmission
] sitemap [http://s1.shard.jp/olharder/autodesk-inventor.html autopage rs 720lcd review
] [http://s1.shard.jp/losaul/diabetes-australia.html australian universities ranked
] domain [http://s1.shard.jp/losaul/australian-music.html novatel hotels australia
] [http://s1.shard.jp/galeach/new108.html aldehyde dehydrogenase asians alcohol treatment
] [http://s1.shard.jp/olharder/auto-buy-com.html auto guard car alarm
] [http://s1.shard.jp/olharder/tactical-automated.html shipping boxes for auto glass
] [http://s1.shard.jp/olharder/auto-car-guys.html auto body parts manufacure
] [http://s1.shard.jp/bireba/antivirus-services.html top antivirus for 2005
] [http://s1.shard.jp/bireba/anyware-antivirus.html avg vs avast antivirus
] [http://s1.shard.jp/frhorton/ank33l6la.html kalulu south africa
] [http://s1.shard.jp/losaul/unley-council-south.html australian food industry conference
] http [http://s1.shard.jp/frhorton/bc7zse5ug.html white south african culture
] [http://s1.shard.jp/bireba/symantec-antivirus.html panda titanium antivirus plus
] [http://s1.shard.jp/losaul/liberal-party.html subaru australia
] [http://s1.shard.jp/galeach/new79.html animals of the asian rainforest
] [http://s1.shard.jp/olharder/autores-romanticos.html autoanything coupon free
] [http://s1.shard.jp/galeach/new111.html asian black hardcore
] page [http://s1.shard.jp/galeach/new50.html mild dysplasia leep
] [http://s1.shard.jp/losaul/job-agencies-sydney.html deception bay australia
] [http://s1.shard.jp/galeach/new125.html ophthalmic lens in asia
] [http://s1.shard.jp/olharder/wheels-and-deals.html autopilot kota minn motor trolling
] [http://s1.shard.jp/losaul/australian-citizenship.html business sales australia
] [http://s1.shard.jp/galeach/new43.html asian girl hot little
] [http://s1.shard.jp/olharder/audi-automotive.html autovermietung koeln
] asian hoe hot [http://s1.shard.jp/frhorton/4dyaal72j.html african american design hair
] url [http://s1.shard.jp/frhorton/71w3q2xvj.html africa holiday resort south
] [http://s1.shard.jp/olharder/accessory-automotive.html kruse auto auction
] chicago asian singles [http://s1.shard.jp/losaul/tents-australia.html swann insurance australia
] [http://s1.shard.jp/bireba/symantec-antivirus.html symantec antivirus corporate edition 10.0 2.2000
] [http://s1.shard.jp/frhorton/vjlche4gq.html african congo grey timneh
] [http://s1.shard.jp/bireba/review-antivirus.html norton antivirus 2005 download free
] top [http://s1.shard.jp/galeach/new130.html asian pusy
] [http://s1.shard.jp/frhorton/3l77ipk2f.html south singapore africa travel advisory
] [http://s1.shard.jp/bireba/avast-free-antivirus.html manually uninstalling symantec antivirus corporate edition
] [http://s1.shard.jp/olharder/automobile-bmw.html grand theft auto san andreas pictures of cars
]
http://www.textletoeltd.com
æÂ¡è¿Âå 堥OWASPå°ç£åÂÂæÂÂï¼ÂãÂÂç¶²ç«Âå®Âå ¨çÂÂ第ä¸ÂæÂ¥ï¼Âå¾Âå 堥OWASPå°ç£åÂÂæÂÂéÂÂå§ÂãÂÂãÂÂ
<paypal>Taiwan</paypal>
å°ç£åÂÂæÂÂæÂÂé·é»ÂèÂÂæÂÂå ÂçÂÂï¼ÂWayne Huangï¼ÂæÂ¨åÂÂæÂÂå·¥ä½ÂÃ¥ÂÂä»Âè¡·å¿Âè¯å®ÂæÂ¨çÂÂÃ¥ÂÂèÂÂï¼Âä¸Â管æÂ¨å¨ä½ÂèÂÂï¼ÂçÂÂè³æÂ¨å æÂ¾çÂÂä¸Â網路足跡æÂ¼å°ç£ï¼ÂæÂÂè¬ÂæÂ¨é¡ÂæÂÂè·Â大家ä¸Âèµ·åÂÂ享ï¼Âè®ÂæÂÂÃ¥ÂÂç¨æÂ´å¤Âä¸ÂÃ¥ÂÂçÂÂè§Â度ä¾Â檢è¦ÂWebå®Âå ¨çÂÂ趨å¢ãÂÂå¨Âè ãÂÂÃ¥ÂÂé¡ÂèÂÂ解決æÂ¹æ¡ÂãÂÂ
- 1 æÂ¡è¿Âå Âè¨ OWASP å°ç£åÂÂæÂÂ
- 2 æÂÂæÂ°æ´»åÂÂ
- 3 æÂ¡è¿ÂæÂ¨çÂÂÃ¥ÂÂèÂÂ
- 4 æÂÂéÂÂOWASP (About OWASP)
- 5 OWASP å°ç£åÂÂæÂ (OWASP Taiwan Chapter)
- 6 OWASP Taiwan
- 7 Participation
- 8 Sponsorship/Membership
- 9 å Âè²»å 堥OWASPå°ç£åÂÂæÂÂ
- 10 OWASPå°ç£åÂÂæÂ é¨è½格 blog
- 11 å¦Âä½Âå 堥æÂÂå¡
- 12 è¿ÂæÂÂæ¶ÂæÂ¯
- 13 ç¶²ç«ÂèÂÂWebæÂÂÃ¥ÂÂçÂÂäºÂ大è³Âå®Âå°å¢Â
- 14 æÂÂæÂ°2007å¹´OWASPÃ¥ÂÂ大Webè³Âå®Âæ¼Âæ´ (2007 OWASP Top 10)
- 15 æÂÂå¡åÂÂ表 (Member List)
æÂ¡è¿Âå Âè¨ OWASP å°ç£åÂÂæÂÂ
æÂÂæÂ°æ´»åÂÂ
第ä¸Âå±ÂOWASPå®ÂæÂ¹äºÂ洲年æÂÂ(OWASP Asia 2007)
Security 3.0 in Web 2.0 Age â Practices and Challenges of Web 2.0 Security
[OWASP_AppSec_Asia_2007 ]
Whitehat SecurityãÂÂç¾ÂÃ¥ÂÂéÂÂéÂÂ(American Express)ãÂÂé¿碼ç§ÂæÂÂ(Armorize)ãÂÂQualysçÂÂè·¨åÂÂä¼Âæ¥ÂèÂÂè³Âå®Âå ¬å¸çÂÂé«ÂéÂÂ主管èÂÂé¦Âå¸Âç Âç©¶å¡é½ÂèÂÂå°ç£ï¼ÂæÂ¨çÂ¥éÂÂä»ÂÃ¥ÂÂå¦Âä½ÂçÂÂå¾ Web 2.0æÂÂ代习Security 3.0Ã¥ÂÂï¼Âå°Âå°ç£èÂÂå ¨çÂÂçÂÂ嫿ÂÂæÂ¯ä»Â麼ï¼ÂæÂÂæÂ¿åºÂãÂÂä¼Âæ¥ÂèÂÂä¸Âè¬使ç¨è åÂÂ該å¦Âä½Âå æÂÂï¼Âå¾Âä¸Âé¢éÂÂäºÂ2007å¹´çÂÂè³Âå®ÂçÂÂ大æÂ°èÂÂï¼ÂéÂÂé²èÂÂæÂÂ樣çÂÂè¨ÂæÂ¯ï¼Â
- 5æÂÂ11æÂ¥èµ·ï¼ÂGoogleéÂÂå§Âç£æÂ§éÂÂé§Âç¶²ç«Âï¼Â並貼ä¸Âå±éª網ç«Âä¹Âæ¨Â籤!
- 5æÂÂ15æÂ¥æÂÂOWASPå ¬ä½Â2007å¹´æÂÂæÂ°çÂÂÃ¥ÂÂ大Webå¼±é»Âï¼Âè·¨ç«Âè ³æÂ¾ÂȾÂÂ(XSS)ç»ä¸Âæ¦Âé¦Â!
- 6æÂÂ6æÂÂ¥IBM購併Watchfireï¼ÂHPé¨å³æÂ¼6æÂÂ19æÂ¥è³¼ä½µSPI Dynamics!èÂÂå åÂÂçÂÂCenzic以滲éÂÂ測試æÂÂè¡ÂæÂ¼6æÂÂ18æÂ¥ç²å¾Âç¾ÂÃ¥ÂÂå°Âå©!
- Web 2.0çÂÂè³Âå®Âå¨Âè ï¼Âå æÂÂä¹ÂéÂÂï¼ÂSecurity 3.0ï¼ÂæÂÂÃ¥ÂÂçÂÂ實åÂÂæ¡Âä¾Âï¼Â
第ä¸Âå±ÂOWASPå®ÂæÂ¹äºÂ洲年æÂÂå°ÂæÂ¼9æÂÂ27æÂÂ¥(é±åÂÂ)ä¸ÂÃ¥ÂÂ1é»ÂæÂ¼å°大é«é¢åÂÂéÂÂæÂÂè°ä¸Âå¿Â201室(å°åÂÂå¸Âä¸ÂæÂ£åÂÂå¾Âå·Âè·¯äºÂèÂÂ)èÂÂ辦ï¼ÂæÂ¡è¿ÂæÂ¨ä¾Âå ±è¥ÂçÂÂèÂÂï¼Â滿è¼ÂèÂÂæÂ¸!éÂÂæÂÂæÂ´å¤Â...
第ä¸Âå±Âå°ç£é§Â客年æÂÂ(HIT 2007)
第ä¸Âå±Âå°ç£é§Â客年æÂÂ(HIT 2007)å·²æÂ¼2007å¹´7æÂÂ21æÂÂ¥(é±åÂ
Â)è³22æÂÂ¥(鱿ÂÂ¥)å¨åÂÂç«Âèºç£ç§ÂæÂÂ大å¸åÂ
¬é¤¨æ ¡åÂÂÃ¥ÂÂ滿è½å¹Âï¼Âæ´»åÂÂçÂÂæ³Â空åÂÂï¼Â詳æÂÂ
è«Â覠HIT 2007 å®ÂæÂ¹ç¶²ç«Â:
http://hitcon.org
æÂ¡è¿ÂæÂ¨çÂÂÃ¥ÂÂèÂÂ
å 堥OWASPå°ç£åÂÂæÂÂä¸ÂéÂÂä»»ä½Âè²»ç¨ï¼ÂæÂÂå¡è³Âæ ¼å®Âå ¨éÂÂæÂ¾çµ¦ä»»ä½Âå°ÂæÂ¼æÂÂç¨ç¨Âå¼Âå®Âå ¨æÂÂèÂÂè¶£çÂÂ人士@æÂÂÃ¥ÂÂé¼Â嵿ÂÂå¡æÂ¼OWASPå°ç£åÂÂæÂÂÃ¥ÂÂ享ä»ÂÃ¥ÂÂçÂÂçÂ¥èÂÂ並æÂÂä¾Âå°Âé¡Âæ¼Âè¬Âï¼ èÂÂå¨å 堥æÂÂå¡åÂÂï¼Âè«ÂæÂ¨ä»Âç´°é±è®ÂÃ¥ÂÂæÂÂæÂÂ塿ÂÂÃ¥ÂÂã èÂ¥è¦Âå 堥æÂŒÂÂæÂÂçÂÂmailing listï¼Âè«Âé£çµÂå°mailing listç¶²é Âï¼ æÂÂæÂÂçÂÂæ´»åÂÂè¨Âè«ÂèÂÂæ´»åÂÂå°é»Âå°ÂéÂÂéÂÂéÂÂÃ¥ÂÂ渠å®ä¾Âè¨Âè«Âï¼ æÂ¨ä¹Âå¯以å¾Âemail è¨Âè«ÂÃ¥ÂÂ份ä¸ÂæÂ¾å°æÂÂÃ¥ÂÂä¹ÂÃ¥ÂÂè¨Âè«ÂçÂÂÃ¥ÂÂ份ã æÂÂå¾ÂæÂÂéÂÂæÂ¨ï¼ÂÃ¥ÂÂå 活åÂÂÃ¥ÂÂï¼Âè«ÂÃ¥ÂÂ次檢æÂ¥æÂ¨mailing listçÂÂ信件以確å®Âæ´»åÂÂå°é»ÂèÂÂæÂÂéÂÂï¼ÂæÂÂæÂ¯ä»»ä½ÂæÂÂéÂÂæ´»åÂÂè¨ÂéÂÂçÂÂäºÂé  ãÂÂ
æÂÂéÂÂOWASP (About OWASP)
OWASP(éÂÂæÂ¾Webè»Âé«Âå®Âå ¨è¨Âç« - Open Web Application Security Project)æÂ¯ä¸ÂÃ¥ÂÂéÂÂæÂ¾ç¤¾ç¾¤ãÂÂéÂÂçÂÂå©æÂ§çµÂç¹Âï¼Âç®åÂÂå ¨çÂÂæÂÂ82Ã¥ÂÂÃ¥ÂÂæÂÂè¿ÂèÂŒÂÂæÂÂå¡ï¼Â堶主è¦Âç®æ¨ÂæÂ¯ç Âè°åÂÂå©解決Webè»Âé«Âå®Âå ¨ä¹Âæ¨ÂæºÂãÂÂ工堷èÂÂæÂÂè¡ÂæÂÂä»¶ï¼Âé·æÂÂè´åÂÂæÂ¼åÂÂå©æÂ¿åºÂæÂÂä¼Âæ¥ÂçÂÂ解並æÂ¹åÂÂç¶²é ÂæÂÂç¨ç¨Âå¼ÂèÂÂç¶²é ÂæÂÂÃ¥ÂÂçÂÂå®Âå ¨æÂ§ãÂÂç±æÂ¼æÂÂç¨ç¯ÂÃ¥ÂÂæÂ¥å»£ï¼Âç¶²é ÂæÂÂç¨å®Â堨已ç¶ÂéÂÂ漸çÂÂÃ¥ÂÂå°éÂÂè¦Âï¼Â並漸漸æÂÂçºå¨å®Âå ¨é ÂÃ¥ÂÂçÂÂä¸ÂÃ¥ÂÂç±éÂÂ話é¡Âï¼Âå¨æÂ¤åÂÂæÂÂï¼Âé§Â客åÂÂä¹ÂæÂÂæÂÂçÂÂå°Âç¦é»Âè½Âç§»å°網é ÂæÂÂç¨ç¨Âå¼ÂéÂÂç¼æÂÂæÂÂæÂÂç¢çÂÂçÂÂå¼±é»Âä¾Âé²è¡ÂæÂȾÂÂèÂÂç ´å£ÂãÂÂ
ç¾ÂÃ¥ÂÂè¯é¦貿æÂÂå§Â塿ÂÂ(FTC)å¼·çÂÂ建è°æÂÂæÂÂä¼Âæ¥ÂéÂÂéµ循OWASPæÂÂç¼ä½ÂçÂÂÃ¥ÂÂ大Webå¼±é»Âé²è·å®ÂÃ¥ÂÂãÂÂç¾ÂÃ¥ÂÂÃ¥ÂÂé²é¨亦åÂÂçºæÂÂ佳實åÂÂï¼ÂÃ¥ÂÂéÂÂä¿¡ç¨å¡è³ÂæÂÂå®Âå ¨æÂÂè¡ÂPCIæ¨ÂæºÂæÂ´å°Âå ¶åÂÂçº忠è¦Âå Âä»¶ãÂÂç®åÂÂOWASPæÂÂ30å¤ÂÃ¥ÂÂé²è¡Âä¸ÂçÂÂè¨Âç«ï¼Âå æÂ¾ÂÂçÂ¥åÂÂçÂÂOWASP Top 10(Ã¥ÂÂ大Webå¼±é»Â)ãÂÂWebGoat(代罪ç¾Âç¾Â)ç·´ç¿Âå¹³å°ãÂÂå®Âå ¨PHP/Java/ASP.NetçÂÂè¨Âç«ï¼ÂéÂÂå°Âä¸ÂÃ¥ÂÂçÂÂè»Âé«Âå®Âå ¨åÂÂé¡Âå¨é²è¡Âè¨Âè«ÂèÂÂç Âç©¶ãÂÂ
ç¶貴å®ä½Â決å®ÂéÂÂæÂ¾ç¶²é ÂæÂÂÃ¥ÂÂæÂÂï¼Â就忠é Âè®Âä¾ÂèªæÂ¼å ¨çÂÂçÂÂç¶²é Âè«Âæ±Âé²堥å®ä½Âå §é¨çÂÂç¶²é Â伺æÂÂå¨ãÂÂé§Â客å¯以èÂÂç±é±èÂÂå¨åÂÂæ³ÂçÂÂç¶²é Âè«Âæ±Âå §ï¼ÂéÂÂéÂÂé²ç«çÂÂãÂÂ堥侵åµ測系統æÂÂå ¶ä»Âé²禦系統çÂÂåµ測ï¼Âå ÂèÂÂçÂÂä¹ÂçÂÂé²堥å®ä½Â堧鍿ÂÂèÂÂç±å®ä½Âç¶²ç«Âå  ç¶跳æÂ¿èÂÂä¸Âç¹¼ç«ÂèÂÂÃ¥ÂÂå ¶ä»ÂÃ¥ÂÂ害è ç¼åÂÂæÂȾÂÂãÂÂéÂÂæÂÂå³èÂÂä¼Âæ¥ÂçÂÂç¶²é Âç¨Âå¼Â碼ä¹Âå¿ é ÂæÂÂçºæ©ÂéÂÂ(æ§Â)å®ä½Âå¨éÂÂçÂÂå®Âå ¨é²è·ä¹Âä¸Âï¼Âç¶å®ä½Âç¶²é ÂæÂÂÃ¥ÂÂçÂÂè¦Â模èÂÂè¤ÂéÂÂæÂ§å¢Âå æÂÂï¼Âå®ä½ÂæÂ´é²æÂ¼å¤ÂçÂÂ風éªä¹ÂéÂÂ漸å¢Âå ãÂÂ
OWASP å°ç£åÂÂæÂ (OWASP Taiwan Chapter)
- ç¶²é Â:http://www.owasp.org.tw
- éÂȎµ:[email protected]
- 群çµÂ:[email protected]
- ä½ÂÃ¥ÂÂ:å°åÂÂå¸Â115Ã¥ÂÂ港åÂÂä¸ÂéÂÂè·¯19-13èÂÂ(Ã¥ÂÂ港è»Âé«ÂÃ¥ÂÂÃ¥ÂÂ)Eæ£Â5æ¨Â554室
OWASP Taiwan
Welcome to the Taiwan chapter homepage. The chapter leader is Wayne Huang
Participation
OWASP Foundation (Overview Slides) is a professional association of global members and is open to anyone interested in learning more about software security. Local chapters are run independently and guided by the Chapter_Leader_Handbook. As a 501(c)(3) non-profit professional association your support and sponsorship of any meeting venue and/or refreshments is tax-deductible. Financial contributions should only be made online using the authorized online chapter donation button. To be a SPEAKER at ANY OWASP Chapter in the world simply review the speaker agreement and then contact the local chapter leader with details of what OWASP PROJECT, independent research or related software security topic you would like to present on.
Sponsorship/Membership
to this chapter or become a local chapter supporter.
Or consider the value of Individual, Corporate, or Academic Supporter membership. Ready to become a member?
Chapter meetings are held several times a year, typically in the offices of our sponsor.
Please subscribe to the mailing list for meeting announcements.
å Âè²»å 堥OWASPå°ç£åÂÂæÂÂ
å åÂ
Â¥OWASPå°ç£åÂÂæÂÂä¸ÂéÂÂä»»ä½Âè²»ç¨
å åÂ
¥æÂÂå¡æÂ¹æ³Âè«Âè¦ÂæÂ¬é Âä¸ÂæÂ¹ å¦Âä½Âå åÂ
¥æÂÂå¡
å åÂ
Â¥OWASPå°ç£åÂÂæÂÂä¸ÂéÂÂä»»ä½Âè²»ç¨ï¼ÂæÂÂå¡è³Âæ ¼å®ÂÃ¥Â
¨éÂÂæÂ¾çµ¦ä»»ä½Âå°ÂæÂ¼æÂÂç¨ç¨Âå¼Âå®ÂÃ¥Â
¨æÂÂèÂÂè¶£çÂÂ人士ï¼Â
æÂÂÃ¥ÂÂé¼Â嵿ÂÂå¡æÂ¼OWASPå°ç£åÂÂæÂÂÃ¥ÂÂ享ä»ÂÃ¥ÂÂçÂÂçÂ¥èÂÂ並æÂÂä¾Âå°Âé¡Âæ¼Âè¬Âï¼Â
èÂÂå¨å åÂ
¥æÂÂå¡åÂÂï¼Âè«ÂæÂ¨ä»Âç´°é±è®ÂÃ¥ÂÂæÂÂæÂÂ塿ÂÂÃ¥ÂÂãÂÂ
èÂ¥è¦Âå åÂ
¥æÂŒÂÂæÂÂçÂÂmailing listï¼Âè«Âé£çµÂå°mailing listç¶²é Âï¼Â
æÂÂæÂÂçÂÂæ´»åÂÂè¨Âè«ÂèÂÂæ´»åÂÂå°é»Âå°ÂéÂÂéÂÂéÂÂÃ¥ÂÂæ¸Â
å®ä¾Âè¨Âè«Âï¼Â
æÂ¨ä¹Âå¯以å¾Âemail è¨Âè«ÂÃ¥ÂÂ份ä¸ÂæÂ¾å°æÂÂÃ¥ÂÂä¹ÂÃ¥ÂÂè¨Âè«ÂçÂÂÃ¥ÂÂ份ãÂÂ
æÂÂå¾ÂæÂÂéÂÂæÂ¨ï¼ÂÃ¥ÂÂå 活åÂÂÃ¥ÂÂï¼Âè«ÂÃ¥ÂÂ次檢æÂ¥æÂ¨mailing listçÂÂ信件以確å®Âæ´»åÂÂå°é»ÂèÂÂæÂÂéÂÂï¼ÂæÂÂæÂ¯ä»»ä½ÂæÂÂéÂÂæ´»åÂÂè¨ÂéÂÂçÂÂäºÂé  ãÂÂ
OWASPå°ç£åÂÂæÂ é¨è½格 blog
éÂÂè¦Âä¸ÂæÂÂè³Âå®ÂæÂ å ±ï¼ÂæÂÂè¡ÂÃ¥ÂÂæÂÂï¼Âå¸Âå ´è³Âè¨ÂÃ¥ÂÂï¼Â
æÂ¡è¿Â常侠OWASPå°ç£åÂÂæÂ é¨è½格 blog
å¦Âä½Âå 堥æÂÂå¡
æÂ¡è¿Âå Âè²»å 堥OWASP Taiwanå°ç£åÂÂæÂÂï¼Âå 堥æÂ¹å¼ÂæÂÂä¸Â種ï¼Âç·Âä¸Âå ±åÂÂï¼Âemailå ±åÂÂ以åÂÂå³çÂÂå ±åÂÂï¼ å·¥ä½ÂÃ¥ÂÂä»ÂæÂÂæÂÂçºÂéÂÂçÂ¥æÂÂæÂÂæÂÂ塿ÂÂéÂÂOWASPæÂÂæÂ°æ´»åÂÂè³Âè¨ÂèÂÂ座è«ÂæÂÂè°ç¨Â.
ç·Âä¸Âå ±åÂÂ
è«ÂæÂÂæÂ¤å¡«å¯«ç·Âä¸Âå ±åÂÂå®
Emailå ±åÂÂ
è«Âemailï¼Â[email protected]å 堥å°ç£åÂÂæÂÂ,è«Â註æÂÂä¸ÂÃ¥ÂÂè³Âè¨Â.
- å§ÂÃ¥ÂÂ
- å®ä½Â
- è·稱
- éÂȌÂÂéµ件
- è¯絡é»話
å³çÂÂå ±åÂÂ
è«ÂÃ¥ÂÂå°æÂ¤å ±åÂÂ表,填寫å¾Âå³çÂÂè³(02)6616-1100å³å¯.
è¿ÂæÂÂæ¶ÂæÂ¯
- WebæÂÂç¨ç¨Âå¼Âå®Âå ¨ç Âè¨ÂæÂÂ:å¨2008å¹´7æÂÂ22æÂ¥èµ·ï¼Âè¡ÂæÂ¿é¢ç ÂèÂÂæÂÂèÂÂè³ÂéÂÂå®Âå ¨æÂÂå ±æÂÂæÂÂä¸Âå¿ÂèÂÂ辦ä¹ÂæÂ¿åºÂæ©ÂéÂÂè»Âé«Âå®Âå ¨æÂÂè¡Âç Âè¨ÂæÂÂï¼ÂéÂÂéÂÂWeb æÂÂç¨ç¨Âå¼Âå®Âå ¨åÂÂèÂÂæÂÂå¼Âå°Âå ¥æ¡Âä¾Âï¼ÂçÂÂè§£WebæÂÂç¨ç¨Âå¼Âå¯è½弱é»Âï¼ÂæÂÂä¾ÂÃ¥ÂÂæ©ÂéÂÂ(æ§Â)å§Âå¤Â管çÂÂÃ¥ÂÂèÂÂãÂÂ
- Webå®Âå ¨æÂ°èÂÂ:å¨2007å¹´6æÂÂ11æÂ¥ï¼ÂiThomeå ±å°ÂãÂÂç¶²ç«Âå®Â堨潰堤ï¼Âä¸Âå®Â堨就æ²Â顧客ãÂÂï¼Â深堥追蹤GoogleæÂÂå°Âå¼ÂæÂÂå æÂÂæÂ¡æÂÂç¶²ç«Âä¹ÂæÂ°æÂªæÂ½ï¼Âå ¶æÂÂå°ÂçµÂæÂÂæÂÂçºæÂÂè³Âå®ÂÃ¥ÂÂé¡ÂçÂÂç¶²ç«Âè²¼ä¸Âè¦åÂÂæ¨Â籤ï¼Â並éÂȾ¢使ç¨è ç´æÂ¥çÂÂ覽ãÂÂ
- OWASPå°ç£åÂÂæÂÂÃ¥ÂÂå±Â:å¨2007å¹´4æÂÂ16è³18æÂ¥ï¼Âå°åÂÂÃ¥ÂÂéÂÂè³Âå®Âå±Â(http://www.secutech.com/tw/is/index.asp) éÂÂéÂÂç»場ï¼ÂOWASPå°ç£åÂÂæÂÂéÂÂæÂ¨èÂÂè¨æÂ¤ä½ÂA402èÂÂA404ï¼Âå³å¯ç²å¾ÂWebè³Âå®Âå Âç¢Âä¸Âå¼µï¼Â並親èªåÂÂæÂÂé«Âé©Âæ¯Â滲éÂÂ測試ãÂÂå¼±é»Â稽核çÂÂå³統è³Âå®Â檢測æÂ¹å¼ÂæÂ´çºåªç°çÂÂèªåÂÂæºÂ碼檢測æÂÂè¡ÂãÂÂ
- Webå®Âå ¨æÂ°èÂÂ:å¨2007å¹´4æÂÂ11æÂ¥ï¼ÂiThomeå ±å°ÂãÂÂOWASPå°ç£åÂÂæÂÂæÂÂç«ÂæÂÂå¡å Âè²»æÂÂÃ¥ÂÂä¸Âï¼Âç¼å©æÂÂÃ¥ÂÂWebå®Âå ¨é²è·è·Âä¸ÂÃ¥ÂÂéÂÂ趨å¢ãÂÂãÂÂ
- Webå®Âå ¨æÂ°èÂÂ:å¨2007å¹´4æÂÂ9æÂ¥ï¼ÂèÂÂæÂÂæÂ¥å ±å ±å°Âå°ç£已æÂÂESPNé«Âè²å°çÂÂ許å¤ÂèÂÂæ°Âç¾çÂÂæ´»æÂ¯æÂ¯ç¸éÂÂçÂÂäºÂÃ¥ÂÂä¸ÂÃ¥ÂÂå®Âç¶²ï¼Âä¸ÂæÂÂ以ä¾Âé¸çºÂéÂÂé§Â客æ¤Âå ¥æÂ¨é¦¬å¾ÂéÂÂï¼ÂèÂÂç±è»Âé«Âå» åÂÂå°Âç¡修è£Âç¨Âå¼ÂçÂÂãÂÂé¶æÂÂå·®æÂȾÂÂãÂÂï¼ÂZero-Day Attackï¼Âï¼Âç¡è¾Â使ç¨è åªè¦Âé£ä¸Âç¶²çÂÂ覽ï¼Âé»蠦就ä¸ÂçÂÂï¼Âè¼Âè 帳èÂÂãÂÂå¯Â碼éÂÂç«Âï¼Â身åÂÂ被çÂÂç¨ï¼ÂéÂÂè æ©ÂæÂÂè³ÂæÂÂå¤Âæ´©æÂÂ財ç©æÂÂ失ãÂÂ
- WebæÂÂç¨ç¨Âå¼Âå®Âå ¨ç Âè¨ÂæÂÂ:å¨2007å¹´3æÂÂ27è³4æÂÂ11æÂ¥ï¼Âè¡ÂæÂ¿é¢ç ÂèÂÂæÂÂèÂÂè³ÂéÂÂå®Âå ¨æÂÂå ±æÂÂæÂÂä¸Âå¿ÂèÂÂ辦ä¹ÂæÂ¿åºÂè³ÂéÂÂå®Âå ¨é²è·巡迴ç Âè¨ÂæÂÂï¼Âè³Âå®Âç¼å±Â趨å¢åÂÂ網路æÂÂç¨æÂÂÃ¥ÂÂè³Âè¨Âå®Âå ¨ï¼ÂæÂ¡è¿ÂæÂ¿åºÂæ©ÂéÂÂ(æ§Â)負責è³ÂéÂÂå®Âå ¨ç¸éÂÂ人å¡踴èºÂÃ¥ÂÂå ãÂÂNEW!ç Âè¨ÂæÂÂè¬Â義ä¸Âè¼Â
- Webå®Âå ¨æÂ°èÂÂ:å¨2007å¹´3æÂÂ21æÂ¥ï¼Âä¸ÂÃ¥ÂÂæÂÂ報報å°ÂãÂÂä¸Âç¶²æÂÂä¸Âå®Âå ¨åÂÂå®¶ï¼Âå°ç£é«Â屠第äºÂãÂÂï¼Âç±æ³ÂÃ¥ÂÂé¨調æÂ¥å±ÂãÂÂÃ¥ÂÂäºÂå±ÂçÂÂå®ä½Âå ±åÂÂéÂÂå°Âå°ç£網路å®Âå ¨é²è¡Âè§Âå¯Âç¼ç¾ï¼Âå°ç£網路çÂÂè³Âè¨Âå®Âå ¨å¨Âè ï¼Âé«Âå± äºÂ洲第äºÂï¼Âå 次æÂ¼ä¸ÂÃ¥ÂÂãÂÂ2007å¹´åÂÂè³ä»Âï¼Âå¹³åÂÂæ¯Â天齿ÂÂç¼çÂÂ5ä»¶é§Â客堥侵äºÂä»¶ãÂÂ
- Webå®Âå ¨æÂ°èÂÂ:å¨2007å¹´3æÂÂ8æÂ¥ï¼ÂæÂ±æ£®æÂ°èÂÂå ±å°ÂãÂÂå°ç£é§Â客æÂȾÂÂäºÂä»¶åÂÂå°Âé¾Âä¹Âå ï¼Â90ï¼ éÂÂè¡ÂæÂ¾éÂÂ堥侵ãÂÂï¼Âç¶èÂÂ許å¤Âä¼Âæ¥Âé½以æ²ÂæÂÂé Âç®Âçºç±ï¼Âä¸Âé¡ÂæÂÂå¢Âå é²èÂᏬÂÃ¥ÂÂèÂÂ人åÂÂï¼Â被é§Â客ç«ÂæÂ¹å ¥ä¾µç¶²é Âï¼Âä¸ÂçÂÂè§£èÂÂå¾Âå´éÂÂçÂÂæÂÂ義ï¼Âç¶²é ÂæÂ¹åÂÂå¾Âï¼Â並æ²ÂæÂÂå¢Âå é²èÂᏬÂÃ¥ÂÂï¼ÂçÂÂè³éÂÂæÂÂå®ä¸Âä¼Âæ¥Â被é§Âé£çºÂé«ÂéÂÂ82次ãÂÂÃ¥ÂÂæÂ°èÂÂé£çµÂ
ç¶²ç«ÂèÂÂWebæÂÂÃ¥ÂÂçÂÂäºÂ大è³Âå®Âå°å¢Â
- IT人å¡ä¸Âè¶³
- 缺ä¹Âè³Âå®Âé ÂÃ¥ÂÂå°Âæ¥ÂçÂ¥èÂÂ
- Ã¥ÂÂè½æÂ§é©ÂæÂ¶çº主
- 缺ä¹ÂèªåÂÂÃ¥ÂÂ工堷
- æÂÂæÂ‹ÂÂæÂÂçÂÂå°ÂÃ¥ÂÂå°Âæ¡Â模å¼Âä¸Âå©確ä¿Âå°Âæ¡ÂÃ¥ÂÂ質
æÂÂæÂ°2007å¹´OWASPÃ¥ÂÂ大Webè³Âå®Âæ¼Âæ´ (2007 OWASP Top 10)
Ã¥ÂÂ大Webè³Âå®Âæ¼Âæ´ÂÃ¥ÂÂ表
- A1. 跨網ç«ÂçÂÂ堥侵åÂÂ串(Cross Site Scriptingï¼Â簡稱XSSï¼Â亦稱çº跨ç«Âè ³æÂ¾ÂȾÂÂ)ï¼ÂWebæÂÂç¨ç¨Âå¼Âç´æÂ¥å°Âä¾Âèª使ç¨è çÂÂå·è¡Âè«Âæ±ÂéÂÂÃ¥ÂÂçÂÂ覽å¨å·è¡Âï¼Â使å¾ÂæÂȾÂÂè å¯æÂ·åÂÂ使ç¨è çÂÂCookieæÂÂSessionè³ÂæÂÂèÂÂè½åÂÂÃ¥ÂÂç´æÂ¥ç»堥çºåÂÂæ³Â使ç¨è ãÂÂ
- A2. 注堥缺失(Injection Flaw)ï¼ÂWebæÂÂç¨ç¨Âå¼Âå·è¡Âä¾Âèªå¤Âé¨å æÂ¬è³ÂæÂÂ庫å¨堧çÂÂæÂ¡æÂÂæÂÂ令ï¼ÂSQL InjectionèÂÂCommand InjectionçÂÂæÂȾÂÂå æÂŒÂ¨å §ãÂÂ
- A3. æÂ¡æÂÂæªÂæ¡Âå·è¡Â(Malicious File Execution)ï¼ÂWebæÂÂç¨ç¨Âå¼Âå¼Âå ¥ä¾Âèªå¤Âé¨çÂÂæÂ¡æÂÂæªÂæ¡Â並å·è¡ÂæªÂæ¡Â堧容ãÂÂ
- A4. ä¸Âå®Âå ¨çÂÂç©件åÂÂèÂÂ(Insecure Direct Object Reference)ï¼ÂæÂȾÂÂè å©ç¨WebæÂÂç¨ç¨Âå¼ÂæÂ¬èº«çÂÂæªÂæ¡Âè®ÂÃ¥ÂÂÃ¥ÂÂè½任æÂÂÃ¥ÂÂÃ¥ÂÂæªÂæ¡ÂæÂÂéÂÂè¦Âè³ÂæÂÂï¼Âæ¡Âä¾Âå æÂ¬http://example/read.php?file=../../../../../../../c:\boot.iniãÂÂ
- A5. 跨網ç«ÂçÂÂå½é è¦Âæ± (Cross-Site Request Forgeryï¼Â簡稱CSRF): å·²çÂȌʴWebæÂÂç¨ç¨Âå¼ÂçÂÂÃ¥ÂÂæ³Â使ç¨è å·è¡Âå°æÂ¡æÂÂçÂÂHTTPæÂÂ令ï¼Âä½ÂWebæÂÂç¨ç¨Âå¼ÂÃ¥Âȍ¶æÂÂÃ¥ÂÂæ³ÂéÂÂæ±ÂèÂÂçÂÂï¼Â使å¾ÂæÂ¡æÂÂæÂÂ令被æÂ£å¸¸å·è¡Âï¼Âæ¡Âä¾Âå æÂ¬ç¤¾äº¤ç¶²ç«ÂÃ¥ÂÂ享ç QuickTimeãÂÂFlashå½±çÂÂä¸ÂèÂÂæÂÂæÂ¡æÂÂçÂÂHTTPè«Âæ±ÂãÂÂ
- A6. è³Âè¨ÂæÂÂé²èÂÂä¸Âé©ç¶é¯誤èÂÂç½® (Information Leakage and Improper Error Handling)ï¼ÂWebæÂÂç¨ç¨Âå¼ÂçÂÂå·è¡Âé¯誤è¨ÂæÂ¯å å«æÂÂæÂÂè³ÂæÂÂï¼Âæ¡Âä¾Âå æÂ¬:系統æªÂæ¡Âè·¯å¾ÂçÂÂæÂÂ鲿ÂÂè³ÂæÂÂ庫æ¬Âä½ÂÃ¥ÂÂ稱ãÂÂ
- A7. éÂÂç ´å£ÂçÂÂéÂÂå¥èÂÂé£ç·Â管çÂÂ(Broken Authentication and Session Management)ï¼ÂWebæÂÂç¨ç¨Âå¼Âä¸Âèªè¡ÂæÂ°å¯«çÂÂ身åÂÂé©ÂèÂÂç¸éÂÂÃ¥ÂÂè½æÂÂ缺é·ãÂÂ
- A8. ä¸Âå®Âå ¨çÂÂå¯Â碼å²åÂÂå¨ (Insecure Cryptographic Storage)ï¼ÂWebæÂÂç¨ç¨Âå¼Âæ²ÂæÂÂå°ÂæÂÂæÂÂæÂ§è³ÂæÂÂ使ç¨å å¯ÂãÂÂ使ç¨è¼Âå¼±çÂÂå å¯Âæ¼Âç®Âæ³ÂæÂÂå°ÂéÂÂé°å²åÂÂæÂ¼å®¹æÂÂ被åÂÂå¾Âä¹ÂèÂÂãÂÂ
- A9. ä¸Âå®Âå ¨çÂÂéÂÂè¨Â(Insecure Communication)ï¼Âå³éÂÂæÂÂæÂÂæÂ§è³ÂæÂÂæÂÂ並æÂªä½¿ç¨HTTPSæÂÂå ¶ä»Âå å¯ÂæÂ¹å¼ÂãÂÂ
- A10. çÂÂæÂ¼éÂÂå¶URLÃ¥ÂÂÃ¥ÂÂ(Failure to Restrict URL Access)ï¼ÂæÂÂäºÂç¶²é Âå çºæ²ÂæÂÂæ¬ÂéÂÂæÂ§å¶ï¼Â使å¾ÂæÂȾÂÂè å¯éÂÂéÂÂç¶²åÂÂç´æÂ¥åÂÂÃ¥ÂÂï¼Âæ¡Âä¾Âå æÂ¬å Â許ç´æÂ¥ä¿®æÂ¹WikiæÂÂBlogç¶²é Â堧容ãÂÂ
éÂÂ次OWASPå ¬å¸ÂæÂ°çÂÂTop 10Ã¥ÂÂæÂ åºç®åÂÂçÂÂæÂȾÂÂç¾æ³Âï¼Â以ä»Âå¹´çºä¾Âï¼ÂCross-Site Scripting(XSS)調æÂ´çº10大æÂȾÂÂä¹Âé¦Âï¼ÂçÂÂ實çÂÂÃ¥ÂÂæÂ åºç®åÂÂ網路é£éÂÂèÂÂè©Â欺çÂÂæÂȾÂÂæ¿«ç¨XSSçÂÂæÂ å½¢ï¼ÂäºÂ實ä¸Âï¼Âç¾ÂÃ¥ÂÂÃ¥ÂÂé²é¨çÂÂBSIè¨Âç«(Build-Security In,https://buildsecurityin.us-cert.gov/) Ã¥ÂÂMitreç Âç©¶æ©Âæ§ÂçÂÂCVEè³Âå®ÂèÂÂå¼±æÂ§åÂÂ表(http://cve.mitre.org/) 亦顯示1)Cross Site ScriptingèÂÂ2)SQL Injectionå·²é£çºÂå ©å¹´åÂÂçº堨çÂÂé ÂèÂÂå´éÂÂè³Âå®Âå¼±é»Â.
ç´æÂ¥èÂÂç¨Âå¼Â碼å®Âå ¨åÂÂ質æÂÂéÂÂ
- [å¿ è¦Â*]A1. 跨網ç«Â堥侵åÂÂ串(Cross Site Scripting)
- [å¿ è¦Â*]A2. 注堥缺失(Injection Flaw)
- [建è°*]A3. æÂ¡æÂÂæªÂæ¡Âå·è¡Â(Malicious File Execution)
- [建è°*]A4. ä¸Âå®Âå ¨çÂÂç©件åÂÂèÂÂ(Insecure Direct Object Reference)
- [鏿ÂÂ*]A5. 跨網ç«Âè¦Âæ±Âå½é (Cross-Site Request Forgery)
*OWASPå°ç£åÂÂæÂÂå¼·çÂÂ建è°åÂÂå®ä½Âå¨é²è¡ÂæºÂ碼檢測æÂÂï¼Â尤以æÂ¿åºÂæ©ÂéÂÂ(æ§Â)ï¼ÂæÂÂéµ循æÂ¿åºÂè³ÂéÂÂå®ÂÃ¥Â
¨ä½Âæ¥Âè¦Âç¯Â(http://www.giscc.org.tw) ä¹ÂãÂÂWebæÂÂç¨ç¨Âå¼Âå®ÂÃ¥Â
¨åÂÂèÂÂæÂÂå¼ÂãÂÂï¼Â並å°Â1èÂÂ2Ã¥ÂÂçºå¿Â
è¦Â檢測é Â
ç®ï¼Â3èÂÂ4Ã¥ÂÂçº建è°檢測é Â
ç®ï¼ÂèÂÂ5Ã¥ÂÂçºé¸æÂÂ檢測é Â
ç®ãÂÂ
ï¼Âå¨實åÂÂæ¡Âä¾Âä¸Âï¼Â檢測並修æÂ£1èÂÂ2å³å¯é¿å ÂçµÂ大å¤ÂæÂ¸çÂÂWebè³Âå®Âå¨Âè ãÂÂ
å ä¸Âè¿°æ¼Âæ´ÂéÂÂæÂ¥é æÂÂæÂÂèÂÂWeb伺æÂÂå¨åÂÂå¤Âé¨è¨Âå®ÂæÂÂéÂÂ
- Information Leakage and Improper Error Handling
- Broken Authentication and Session Management
- Insecure Cryptographic Storage
- Insecure Communications
- Failure to Restrict URL Access
æÂÂå¡åÂÂ表 (Member List)
Coming up soon!