【正文】
ally scan your work for open attack vectors – Nessus, FoundScan and the like are useful ? Other open source options available, but require more expertise – Scan both internal and external – Look for what ports are open and ask should they be – Look for known vulnerabilities and get feedback on why they are still there. – Analyze the traffic on the work, what is being sent in clear text? Attack Detection and Prevention ? IDS and IPS – Actively scanning traffic on your work is needed ? Web Applications Firewalls or Reverse Web Proxies – Since your application is being used against you, actively check inputs and outputs. ? Log Monitoring or Security Information and Event Monitoring (SEIM) – Lots of data and events ? Automating this process is the only way to sift through it all effectively Additional Resources ? – Browse the reading room ? webappsbigmistakes12practicaltipsavoid_33038 ? attacks_2053 ? applicationsecuritypractical_1370 – SANS Top 25 Vulnerabilities ? – ESAPI and the Top Ten Web Application Vulnerabilities ? Questions?