what executives need to know about web application development security - redspin information...

Upload: redspin-inc

Post on 10-Apr-2018

217 views

Category:

Documents


0 download

TRANSCRIPT

  • 8/8/2019 What Executives Need to Know About Web Application Development Security - Redspin Information Security

    1/13

    38=: Sko Pmoi) T}kxm4

    Dopzkexmpko) DO ;4:?4

    6::"10?";?11

    6:="368"36=6

    Tmd}pm THID mefoedmt

    xfm xpohkxkleoi Tlcxopm

    Hmsmilzbmex Ikcm D{dimxl kedlpzlpoxm tmd}pkx{ ot

    o `otm pmq}kpmbmex%

    QFKXM ZOZMP

    Qfox Mvmd}xksmt Emmh xlGelq O`l}x Qm` Ozzikdoxkle

    Hmsmilzbmex Tmd}pkx{

  • 8/8/2019 What Executives Need to Know About Web Application Development Security - Redspin Information Security

    2/13

    XO@IM LC DLEXMEXTMvmd}xksm T}bbop{?

    Xfm @}tkemtt Kbzodx lc Tmd}pkx{0

    Flq xfm D}ppmex Hmsmilzbmex Zpldmtt Dpmoxmt Pktg clp4xfm @}tkemtt

    Oe Mvmd}xksm Skmq lc xfm Tlcxqopm Hmsmilzbmex Ikcm D{dim8

    Tmd}pm THID Xfm Tmd}pm Tlcxqopm Hmsmilzbmex Ikcm D{dim=

    @}tkemtt Kbzodx lc Ohhpmttkea Tmd}pkx{ Mopi{3

    Cl}p Txmzt xl Kbbmhkoxmi{ Kbzplsm xfm Tmd}pkx{ lc1[l}p Ozzikdoxklet

    Dledi}tkle6

    oam ? y qqq%pmhtzke%dlb 0::; y Qfkxm

  • 8/8/2019 What Executives Need to Know About Web Application Development Security - Redspin Information Security

    3/13

    Mvmd}xksm T}bbop{Kx kt dlbble gelimham xfox tmd}pkx{ kt elx lem xotg ox o aksme zlkex ke xkbm `}xoe lealkea zpldmtt) {mx d}ppmexi{) xfm bltx dlbble ozzplodf xl tmd}pkea o m`ozzikdoxkle keslismt hlkea o tkeaim tmd}pkx{ xmtx) }t}oii{ o Qm` Ozzikdoxkle Tmd}pkx{Ottmttbmex) fme o hmsmilzbmex zplnmdx kt dlbzimxmh% Qfkim xfkt kt txkii o pmq}kpmbmexlp tmd}pm tlxopm hmsmilzbmex) xfkt zozmp hktd}ttmt f{ tmd}pkx{ emmht xl `mkedlpzlpoxmh mopikmp oeh xfpl}afl}x xfm Tlxopm Hmsmilzbmex Ikm D{dim &THID+% Qm

    oitl hmtdpk`m oe kbzplsmh blhmi lp hmsmilzkea blpm tmd}pm m` ozzikdoxklet xfmtmd}pm THID oeh zplskhm txmzt xfox {l} doe xogm xl kbbmhkoxmi{ kbzplsm xfm tmd}pkx{l {l}p mvktxkea m` ozzikdoxklet oeh hmsmilzbmex zpldmtt% Xfkt ozzikmt xl `lxf emozzikdoxkle hmsmilzbmex oeh oitl mvktxkea ozzikdoxklet xfox fosm `mme pmimotmh xlzplh}dxkle%

    Xfm @}tkemtt Kbzodx lc Tmd}pkx{Xfm ho{t l llzt) m alx fodgmh)`mkea oe oddmzxo`im boeoambmexpmtzletm oxmp oe kexp}tkle opm ileaalem% D}txlbmpt) pma}ioxlpt) oeh xfmemt"pmohkea z}`ikd mvzmdx tmd}pkx{xl `m xfm hmo}ix lzmpoxkea dlehkxkle%Tmd}pkx{ `pmodfmt fosm xpmbmehl}teoedkoi) `poeh oeh pma}ioxlp{ kbzodxoeh xfm llzt pmtzletm kt el ileampo pmotleo`im bmoet l zplxmdxkea oDKTLt dopmmp% Tmd}pkx{ kt mvzmdxmh%

    @}x tmd}pkx{ kt foph% Msme xfm bltx `otkdm` ozzikdoxkle doe `m q}kxm dlbzimv)tl kx kt el t}pzpktm xfox bogkea xfmbtmd}pm kt el mot{ xotg% Kx kt oitl elx

    t}pzpktkea xfox dpmoxkea o m` ozzikdoxklexfox dlbmt l xfm zplh}dxkle ikem ottmd}pm b}tx fosm `mme hmsmilzmh kxftmd}pkx{ ke bkeh tkedm kedmzxkle% Oxmpoii) {l} doex mvzmdx o m` ozzikdoxkledlhmh kxf iodgi}txmp txoehopht oehdlhkea cot xl `m tmd}pm }zle pmimotm%Tmd}pm ozzikdoxklet hl elx n}tx fozzmepoehlbi{7 xfm{ opm zopx l o hmik`mpoxmdlbbkxbmex xl o pl`}tx hmsmilzbmexzpldmtt kxf fkaf tmd}pkx{ txoehopht%Tmd}pm ozzikdoxkle hmsmilzbmex pmq}kpmto ilea"xmpb dlbbkxbmex xl o txp}dx}pmh

    hmsmilzbmex zpldmtt xfox mb`podmt

    tmd}pkx{ ke oii zfotmt l hmsmilzbmexplb kekxkoi pmq}kpmbmext hmsmilzbmex`{ xfm bopgmxkea hmzopxbmex xl lealkealzmpoxklet oeh bokexmeoedm oxmphmzil{bmex%

    Xfm kbzodx l o tmd}pkx{ pmodf dlexke}mtxl pktm ke xmpbt l foph dltxt) ikxkaoxkleoeh iltx `poeh soi}m% Xfm FmopxioehZo{bmex T{txmbt) XNV,XN Txlpmt oehDophT{txmbt) Ked% kedkhmext opmmvobzimt l fl fkaf xfmtm dltxt doe`m> f}ehpmht l bkiiklet l hliiopt oehhl~met l iot}kxt lp Fmopxioeh oeh XNVpmtzmdxksmi{) fkim DophT{txmbt kt n}tx otfmii l kxt lih tmi ot kx iltx mttmexkoii{ oii

    l kxt d}txlbmpt oxmp kxt `pmodf% Ot xfm`}tkemtt kbzodx l o `pmodf kedpmotmt)mvmd}xksmt opm ehkea xfox bovkbk~keatfopmflihmp soi}m bmoet bkekbk~keatmd}pkx{ pktg% Xfkt kt o tkaekdoex txmzfkdf xogmt o boeoambmex dlbbkxbmexxl bogm tmd}pkx{ o pmq}kpmbmex lp oiim` ozzikdoxklet% O aloi l xfkt zozmp ktxl fmiz mvmd}xksmt xfltm ke imohmptfkzplimt) Il@ ABt) DKTLt oeh DKLt `mxxmp }ehmptxoeh xfm tmd}pm THIDtl xfox tmd}pm hmsmilzbmex `mdlbmtkeapokemh ke xfm `}tkemtt d}ix}pm%

    Xfm ho{t lc llzt)

    m alx fodgmh)`mkea oe oddmzxo`im

    boeoambmex

    pmtzletm ocxmp

    oe kexp}tkle opm

    ilea alem%

    oam 0 y qqq%pmhtzke%dlb 0::; y Qfkxm

  • 8/8/2019 What Executives Need to Know About Web Application Development Security - Redspin Information Security

    4/13

    Flq xfm D}ppmex Hmsmilzbmex ZpldmttDpmoxmt Pktg clp xfm @}tkemttFmpm kt o x{zkdoi tdmeopkl ke o m`hmsmilzbmex zplnmdx> hmsmilzbmex ktdlbzimxm oeh xfm ozzikdoxkle kt pmoh{xl `m hmzil{mh lp fot oipmoh{ `mme

    hmzil{mh &tlbmxkbmt lp {mopt ke xfmdotm l imaod{ ozzikdoxklet+ oeh xfmexfm zplnmdx xmob hmdkhmt xl pmq}kpm otmd}pkx{ xmtx `mlpm xfm ozzikdoxkle almtkexl zplh}dxkle xl smpk{ xfox kx kt tmd}pm%Lxme) xfm hmdktkle kt bohm `otmh lemop h}m xl o pmdmex tmd}pkx{ `pmodfpmzlpxmh ke xfm emt lp `{ o dlbzmxkxlplp ot o iotx bke}xm pmq}kpmbmex txkz}ioxmh`{ o `ka dikmex% Ke xfmtm dotmt xfmdltx l o Qm` Ozzikdoxkle Tmd}pkx{Ottmttbmex fot elx `mme odxlpmh kexlxfm hmsmilzbmex `}hamx) fkdf kt lemkehkdoxkle xfox tmd}pkx{ ot o iotx bke}xmxotg ohh"le poxfmp xfoe o dlpm plex"mehpmq}kpmbmex% C}pxfmpblpm) `mdo}tm elxlei{ ot tmd}pkx{ xmtxkea elx `}hamxmh)kx ot elx tdfmh}imh) kexplh}dkea hmio{tkexl xfm pmimotm tdfmh}im%

    Xfkt kt elx oii `oh l dl}ptm) k tmd}pkx{ot elx dletkhmpmh mopi{ le ke xfmhmsmilzbmex zpldmtt xfme hlkea oQm` Ozzikdoxkle Tmd}pkx{ Ottmttbmex)k hlem zplzmpi{ oeh xflpl}afi{) bo{`m xfm tkeaim `kaamtx xfkea xl bkekbk~mxfm pktg l o bonlp tmd}pkx{ `pmodf%

    Flmsmp) kx kt elx kxfl}x kbzodx xl xfmlpaoek~oxkle% Xfmpm opm xl tkaekdoexkbzodxt xfox al `m{leh `}hamx oehzplnmdx boeoambmex tdfmh}imt xfox opmkehkdoxksm l dletkhmpkea tmd}pkx{ ioxm kexfm hmsmilzbmex d{dim%

    ?% T}pzpktmXfm ptx kt t}pzpktm% Hmsmilzbmex xmobtopm lxme t}pzpktmh kxf xfm mvxmex lxfm tmd}pkx{ ktt}mt khmexkmh ot zopx lo Qm` Ozzikdoxkle Tmd}pkx{ Ottmttbmex%@mdo}tm vkea tmd}pkx{ ktt}mt oeh

    boeoakea hmio{t lxme keslism lxfmpapl}zt) xfm t}pzpktm kt mix xfpl}afl}xxfm lpaoek~oxkle% Xfm t{txmb opdfkxmdxemmht xl msoi}oxm xfm tmd}pkx{ cot)xfme xfm hmsmilzmpt emmh xl dlhm }z xfmv% Qfmxfmp xfm hmsmilzbmex xmob ktl}xtl}pdmh lp lpgt ke"fl}tm) xfm{ fosmlxme blsmh le xl lxfmp zplnmdxt `{ xfm

    xkbm xfm `}at opm }edlsmpmh% @mdo}tm`}tkemtt }ekx imohmpt oeh xfm bopgmxkeahmzopxbmex foh el khmo xfox tmd}pkx{tzmdkdoii{ emmhmh xl `m doiimh l}x

    ot o pmq}kpmbmex) xfm{ opm t}pzpktmh `{oe{ ohhkxkleoi dltx oeh tdfmh}im hmio{tdo}tmh `{ xfmtm tmd}pkx{ vmt% Tmd}pkx{pmioxmh tdfmh}im hmio{t doe `m hkd}ixxl mvzioke xl d}txlbmpt ot mii%

    0% PktgXfm tmdleh `ka kbzodx kt pktg% Tlxopmt{txmbt) msme tkbzim lemt) doe `m q}kxmdlbzimv% Qfkim o Qm` OzzikdoxkleTmd}pkx{ Ottmttbmex hlmt o zpmxx{ allhnl` ox ottmttkea pktg) kx kt elx ?::-mmdxksm% Xfmpm opm zlxmexkoi cotke o m` ozzikdoxkle xfox bo{ elx `m}edlsmpmh `{ oe ottmttbmex% Tlbm lxfmtm cot bo{ `m }edlsmpmh b}dfioxmp ot em xmtxkea bmxflhlilakmtopm hmsmilzmh zmpfozt `{ xmtxmpt)lp bo{`m `{ fodgmpt% C}pxfmpblpm)el tlxopm doe `m zmpmdx) xfmpmlpm)lem otzmdx l tmd}pm ozzikdoxklehmtkae kt xl `}kih ke io{mpt l tmd}pkx{)tl k lem otzmdx l xfm tmd}pkx{ blhmiokit) xfm kbzodx l}ih `m bkekbk~mh%Xfkt x{zm l tmd}pkx{ hmtkae bkekbk~mtpktg oeh pmcmdxt oe }ehmptxoehkea lxfm dlbzimvkx{ l tlxopm oeh xfm

    msmp"dfoeakea ioehtdozm l pktg% Kx ktpmoii{ }epmotleo`im xl mvzmdx xfox ohmsmilzbmex zpldmtt xfox kt elx `}kixopl}eh tmd}pkx{) l}ih pmt}ix ke o tmd}pmozzikdoxkle%

    Boe{ boeoampt opm pmtzletk`im lpimaod{ m` ozzikdoxklet xfox mpmkefmpkxmh lp odq}kpmh% Ke xfmtm dotmt oQm` Ozzikdoxkle Tmd}pkx{ Ottmttbmexbkafx m o pmq}kpmbmex xl q}kdgi{ khmexk{tmd}pkx{ pktg% Ke xfmtm tkx}oxklet) t}pzpktm kto aksme) }x kxf em hmsmilzbmex xfmpm

    kt el emmh xl `m t}pzpktmh `{ tmd}pkx{ oxxfm meh l xfm hmsmilzbmex ikm d{dim%Ke xfm liilkea tmdxklet mii hktd}tto em blhmi lp m` hmsmilzbmexxfox kedlpzlpoxmt tmd}pkx{ }z plex oehbkekbk~mt lxf xfm t}pzpktm odxlp oeh xfmpktg kxf o zpmhkdxo`im oeh pmzmoxo`imzpldmtt xl hmsmilz pl`}tx tlxopm xfoxohfmpmt xl tmd}pkx{ `mtx zpodxkdmt%

    oam 4 y qqq%pmhtzke%dlb 0::; y Qfkxm

  • 8/8/2019 What Executives Need to Know About Web Application Development Security - Redspin Information Security

    5/13

    Oe Mvmd}xksm Skmq lc xfm TlcxqopmHmsmilzbmex Ikcm D{dimTmd}pm THID mefoedmt xfm xpohkxkleoitlxopm hmsmilzbmex ikm d{dimxl kedlpzlpoxm tmd}pkx{ ot o `otmpmq}kpmbmex% Tmd}pkx{ omdxt emopi{ oii

    zopxt l o tlxopm t{txmb) plb xfmlzmpoxkea t{txmbt oeh zplapobbkeaioea}oamt }tmh) xl xfm hoxo kx xpoetbkxtoeh txlpmt) xl xfm d}txlbmpt,}tmpt oehxfmkp dozo`kikxkmt% Tl ot {l} bkafx mvzmdx)kedlpzlpoxkea tmd}pkx{ ot o pmq}kpmbmexkbzodxt oii zfotmt l hmsmilzbmex%@mlpm m hktd}tt o tmd}pm THID) imxtpmskm xfm xpohkxkleoi THID%

    Boe{ blhmit fosm `mme hmsmilzmhxl dfopodxmpk~m oeh a}khm xfm tlxopmhmsmilzbmex zpldmtt oeh boe{dlbzoekmt fosm blhkmh xfmtm lpohlzxmh xfmkp le xl t}kx xfmkp tzmdkdemmht% Qfkim modf dlbzoe{t THIDbo{ sop{) xfm{ amempoii{ kedi}hm xfmliilkea l}p zfotmt% L}p hktd}ttkle ltmd}pm THID kii }tm xfkt xmpbkelila{%

    Pmq}kpmbmextXfkt kt fmpm xfm tlxopm ktdledmzx}oik~mh oeh tzmdkd mox}pmt opmhmemh `{ o zplh}dx xmob xl ohhpmtto tzmdkd `}tkemtt emmh lp d}txlbmphmboeh%

    HmtkaeKe xfm hmtkae zfotm hmxokimh tzmdkdoxkletlp xfm tlxopm opm hmsmilzmh oileakxf oe lsmpoii ozzikdoxkle opdfkxmdx}pm%

    HmsmilzbmexH}pkea xfkt zfotm tlxopm hmsmilzmptopm ld}tmh le pkxkea dlhm xl `}kih xfmozzikdoxkle kxtmi% Xfkt zfotm x{zkdoii{

    `maket kxf o fmos{ zplapobbkeambzfotkt) kxf oe kedpmotmh obl}ex lxkbm tzmex le q}oikx{ ott}poedm xmtxkeaot xfm zfotm zplapmttmt%

    Hmzil{bmexXfm eoi zfotm kt lealkea% Kx `maket kxfo eoi xmtx) kedi}hkea tmd}pkx{ xmtxkea)oeh kt xfme pmimotmh% Ledm iksm) xfm m`ozzikdoxkle b}tx `m bokexokemh oileakxf xfm emxlpg oeh tmpsmp meskplebmexke fkdf kx kt fltxmh% @}at opm vmh)mox}pmt opm ohhmh oeh xfm tlxopm ktamempoii{ bokexokemh%

    Xfm boe{ blhmit l THID pmcmdx xfmmsli}xkle l xfl}afx le xfm t}`nmdx &emblhmit opm hmsmilzmh oii xfm xkbm+ oehxfmpm kt o emmh lp lpaoek~oxklet xlimsmpoam o blhmi xfox lpgt lp xfmb%Clp mvobzim) xfm blhmi }tmh `{ ohmhkdoxmh tlxopm dlbzoe{ lpgkea leo `ka zplnmdx) bkafx elx `m ozzplzpkoxmlp o tboii xmob zplnmdx% Qfoxmsmpxfm blhmi oeh eobkea dlesmexklet)xfm `otkd zplapmttkle l hmsmilzbmexkt zpmxx{ dletktxmex% Ke xfm emvx tmdxkle)

    mii tmm fl tmd}pkx{ kt kedlpzlpoxmhkexl xfmtm zfotmt%

    oam 8 y qqq%pmhtzke%dlb 0::; y Qfkxm

  • 8/8/2019 What Executives Need to Know About Web Application Development Security - Redspin Information Security

    6/13

    Cka}pm ? kedlpzlpoxmt kekxkoxksmt ottldkoxmh kxf o tmd}pm THID kexl xfm l}p zfotmt l oxpohkxkleoi THID " pmq}kpmbmext) hmtkae) hmsmilzbmex oeh hmzil{bmex% Xfmtm ohhkxkletopm tfle `mil modf zfotm% Qfkim xfmpm opm o sopkmx{ l o{t xl kexmapoxm o tmd}pmhmsmilzbmex zpldmtt kexl oe lpaoek~oxkle) oeh xfm hkmpkea txp}dx}pmt) aloit oeh

    zpldmttmt l modf lpaoek~oxkle hkdxoxm o cmvk`im ozzplodf) Cka}pm ? pmzpmtmext tlbml xfm bltx `otkd mimbmext xfox opm ikgmi{ zopx l bltx tmd}pm THIDt%

    Xl `mxxmp }ehmptxoeh xfm tmd}pm THID) mii zplskhm o q}kdg hmtdpkzxkle l modf l xfmo`lsm xotgt%

    CLP OII ZFOTMT LC HMSMILZBMEX

    Xfm }ehobmexoi pmq}kpmbmex lp oe{ tmd}pm THID kt mh}doxkle oeh boeoambmexdlbbkxbmex ot xfmtm ozzi{ xl oii zfotmt l xfm blhmi%

    Mh}doxkleTmd}pkx{ mh}doxkle ozzikmt xl oii hmsmilzbmex zplnmdx txogmflihmpt% Clp mvobzim) zplh}dx

    bopgmxkea emmht xl imope o`l}x xfm kbzlpxoedm l tmd}pkx{ oeh xfm eox}pm l tmd}pkx{ pktg%Xfkt kii odkikxoxm hmekea tmd}pkx{ pmq}kpmbmext ke xfm mopi{ zfotmt l hmsmilzbmexoeh oitl fmizt xfmb }ehmptxoeh xfm emmh xl kedlpzlpoxm tmd}pkx{ xmtxkea kexl xfm zplnmdxxkbmikem% Hmsmilzmpt) lp mvobzim) emmh xmdfekdoi mh}doxkle oeh xpokekea le tmd}pmdlhkea) fkim xfm _}oikx{ Ott}poedm &_O+ xmob emmht xl imope fl xl ozzi{ tmd}pkx{xmtxkea xmdfekq}mt% Xfme) opxfmp hle xfm ikem) xfm lzmpoxkleoi KX xmob l}ih emmh xl`m mh}doxmh o`l}x tmd}pkea xfm emxlpg oeh lzmpoxkea t{txmb meskplebmex%

    Boeoambmex DlbbkxbmexTmd}pkx{ txopxt ox xfm xlz% K mvmd}xksm boeoambmex kt elx dlbbkxxmh xl d}ixksoxkea od}ix}pm l tmd}pm ozzikdoxkle hmsmilzbmex) xfme kx kt foph xl kboakem xfox xfm ohhkxkleoikesmtxbmex l o tmd}pm THID l}ih m dletkhmpmh o zpklpkx{ xfpl}afl}x xfm lpaoek~oxkle%Kexmapoxkea tmd}pkx{ kexl o hmsmilzbmex zplnmdx blsmt xfm xkbm oiildoxkle oeh tlbm }hamxkxmbt lp tmd}pkx{ xotgt mopikmp ke xfm zpldmtt% Qfkim xfkt ozzplodf kt khmi{ oddmzxmhot tkaekdoexi{ pmh}dkea xfm tmd}pkx{ pktg l o hoxo `pmodf xfox dl}ih kbzodx `}tkemtt

    Tmd}pm THID Xfm Tmd}pm TlcxqopmHmsmilzbmex Ikcm D{dim

    Cka}pm ?% Tmd}pm THID

    Tmd}pm Tlcxopm

    Hmsmilzbmex Ikcm

    D{dim

    oam = y qqq%pmhtzke%dlb 0::; y Qfkxm

  • 8/8/2019 What Executives Need to Know About Web Application Development Security - Redspin Information Security

    7/13

    zplxo`kikx{ oeh `poeh) kxt xmbzxkea xl kaelpm tmd}pkx{ }exki ioxmp ke xfm zpldmtt ot xfktbkafx tzmmh }z hmsmilzbmex oeh d}x l}x tlbm tflpx xmpb dltxt% Oddmzxkea kedpmbmexoihmsmilzbmex dltx oeh xkbm kedpmotmt lp xfm togm l ilea xmpb pktg boeoambmex kt otxpoxmakd boeoambmex hmdktkle%

    PM_]KPMBMEXT ZFOTM

    Dlbb}ekdoxkleDlbb}ekdoxkle ke xfm dlexmvx l tmd}pm THID bmoet met}pkea xfox oii hmsmilzbmexzplnmdx txogmflihmpt opm oopm xfox tmd}pkx{ kt txpoxmakd xl xfm }tkemtt% Kx kt xfm txoxmbmexxfox ohfmpmedm xl }ehobmexoi tmd}pkx{ `mtx zpodxkdmt) lpaoek~oxkleoi tmd}pkx{ zlikdkmtoeh ozzikdoxkle imsmi tmd}pkx{ pmq}kpmbmext kt dmexpoi xl xfm hmsmilzbmex mlpx% Mopi{opxkd}ioxkle l xfm kbzlpxoedm l xfmtm tmd}pkx{ zpkedkzimt kt o txopxkea zlkex lp met}pkeaxfox xfm zplnmdx hlmt elx iltm tkafx l tmd}pkx{%

    Qm` Ozzikdoxkle Tmd}pkx{ Zlikd{O m` ozzikdoxkle tmd}pkx{ zlikd{ tmpsmt ot xfm hld}bmexmh smptkle l xfm zpmskl}tdlbb}ekdoxkle txmz% Kx hmemt tlbm l xfm fkaf"imsmi `mtx zpodxkdmt) lpaoek~oxkletmd}pkx{ zlikdkmt xfox tzmdkdoii{ ohhpmtt m` ozzikdoxklet oeh tmd}pkx{ pmq}kpmbmextxfox opm ozzikdo`im xl xfm mexkpm zlpxlikl l m` ozzikdoxklet ke o aksme `}tkemtt% Kx kto zlikd{ xfox met}pmt xfox b}ixkzim zplnmdxt kxfke o dlbzoe{ opm ozzi{kea xfm tmd}pm

    THID dletktxmexi{% Xfkt dlhkmt xfm tmd}pm THID oeh bo{ kedi}hm tlbm l xfm `otkd`}kihkea `ildgt tfle ke Cka}pm ? ot txoehopht lp hmsmilzbmex%

    ]tm oeh Bkt"]tm Dotmt]tm dotm blhmikea ke hmsmilzbmex kt o o{ xl dfopodxmpk~m fl }tmpt kexmpodx kxf ot{txmb xl }tm tzmdkd }edxkleoikx{ l xfm tlxopm% ]tm dotmt zplskhm o zpodxkdoi o{xl hmtdpk`m dlbble tdmeopklt lp fl }tmpt kii }tm dmpxoke }edxkleoi pmq}kpmbmext lo t{txmb% Bkt"}tm dotmt opm tkbkiop mvdmzx xfox xfm{ blhmi fl oe oxxodgmp bo{ }tmxfm t{txmb ke o o{ xfox kt elx kexmehmh `{ kxt hmtkaempt xl dlbzplbktm xfm t{txmb%]ehmptxoehkea bkt"}tm dotmt fmizt hmxmpbkem xfm gkeht l dlexplit emmhmh ke xfmozzikdoxkle%

    Tmd}pkx{ Pmq}kpmbmextKe o zpm"tmd}pkx{ lpkmexmh hmsmilzbmex zpldmtt) xfm pmq}kpmbmext zfotm dozx}pmt xfm

    mox}pmt xfox emmh xl `m kedi}hmh ke xfm ozzikdoxkle% Xfkt kt oe lzzlpx}ekx{ xl hmemfox }edxkleoikx{ xfm ozzikdoxkle kii kedi}hm% Ke tmd}pm THID) xfm pmq}kpmbmext zfotmkt mvzoehmh xl kedi}hm oe{ tzmdkd tmd}pkx{ dletkhmpoxklet xfox emmh xl m odxlpmh kexlxfm hmsmilzbmex% Xfkt kt xfm lzzlpx}ekx{ xl tzmdk{ oe{ dlbzikoedm" lp hoxo tmd}pkx{"hpksme tmd}pkx{ pmq}kpmbmext) ot mii ot oe{ keh}txp{"tzmdkd `mtx zpodxkdmt xfox opmpmimsoex xl m` ozzikdoxklet ke amempoi) lp tzmdkd xl oe keh}txp{%

    HMTKAE ZFOTM

    Tmd}pm Opdfkxmdx}pmKe tmd}pm THID) tmd}pm opdfkxmdx}pm pmmpt xl xfm hmtkae dletkhmpoxklet xfox) fmekedlpzlpoxmh ot o }ehobmexoi }kihkea ildg l o t{txmb) bkekbk~m xfm kefmpmex tmd}pkx{

    pktg l oe ozzikdoxkle% Xfmtm kedi}hm hmmetm"ke"hmzxf) ke fkdf xfmpm opm io{mpt ltmd}pkx{ dlexplit kbzimbmexmh t}df xfox k lem okit xfmpm kt oelxfmp io{mp ot o `odg}z%Lxfmp mvobzimt opm> imotx"zpkskimam }tmpt opm lei{ meo`imh kxf xfm bkekb}b imsmi l}edxkleoikx{ emmhmh lp xfmkp }tm7 tmd}pm `{ hmo}ix xfm hmo}ix tmxxkeat l xfm t{txmbopm tmd}pm7 bkekbk~m oxxodg t}podm opmo mvzltm xfm bkekb}b e}b`mp l dpkxkdoi}edxklet xfox bkafx `m s}iempo`im xl oxxodg7 oki tmd}pm k xfm ozzikdoxkle tfl}ih oki) kxhlmt tl ke o o{ xfox hlmt elx mvzltm xfm ozzikdoxkle xl dlbzplbktm7 oslkh tmd}pkx{"`{"l`td}pkx{ xfmpm kt elxfkea plea kxf bkekbk~kea xfm z}`ikd gelimham l {l}pt{txmbt) `}x xfkt kt elx oe ozzplzpkoxm tmd}pkx{ bmot}pm%

    Hmtkae Pmskm,OttmttbmexXfmtm pmmp xl o tkbkiop zpldmtt) fmpm hmtkae pmskm kt dlbzimxmh kexmpeoii{ oeh hmtkaeottmttbmex kt dlbzimxmh `{ oe l`nmdxksm xfkph"zopx{% Ke mkxfmp dotm xfm aloi kt xfm tobm)

    oam 3 y qqq%pmhtzke%dlb 0::; y Qfkxm

  • 8/8/2019 What Executives Need to Know About Web Application Development Security - Redspin Information Security

    8/13

    xl fosm oe l`nmdxksm pmskm l xfm opdfkxmdx}pm) xl met}pm k xfm m` ozzikdoxkle hmtkaekt dletktxmex kxf xfm zplnmdx tmd}pkx{ pmq}kpmbmext oeh mtx"zpodxkdm tmd}pkx{ opdfkxmdx}pmzpkedkzimt%

    Tfkz DpkxmpkoHmekea tzmdkd dpkxmpko xfox b}tx `m bmx `mlpm o zplnmdx kt hmzil{mh met}pmt xfox xfm`otkd tmd}pkx{ l`nmdxksmt kii elx `m lpalxxme ot xfm m` ozzikdoxkle zplnmdx tdfmh}imemopt xfm meh% Clp mvobzim) oe ozzikdoxkle bo{ lei{ m oiilmh xl m pmimotmh k kx kt pmmplb s}iempo`kikxkmt khmexkmh h}pkea xfm eoi Qm` Ozzikdoxkle Tmd}pkx{ Ottmttbmex%

    Oxxodg T}pcodm Oeoi{tktXfm t}podm opmo l o m` ozzikdoxkle pmmpt xl xfm e}b`mp l mox}pmt oeh xfm mvxmexxl fkdf }tmpt doe oddmtt xfmb% Blpm }edxkleoi oddmtt `{ blpm }tmpt kt blpm t}podmopmo% Blpm t}podm opmo pmzpmtmext blpm pktg% Lem aloi l ozzikdoxkle hmtkae tfl}ih`m xl bkekbk~m xfm oxxodg t}podm opmo% Bmot}pkea xfm oxxodg t}podm opmo doe zplskhmoe mmdxksm bmxpkd l pktg oeh m }tmh ot o `otmikem ot xfm t{txmb kt hmsmilzmh xl smpk{xfox xfm oxxodg t}podm opmo fot elx aple% Tkaekdoex aplxf ke oxxodg t}podm opmobo{ pmcmdx dlhkea mpplpt lp mox}pm dpmmz xfox tkaekdoexi{ kedpmotmt lsmpoii pktg%

    Xfpmox BlhmikeaXfpmox blhmikea pmmpt xl o bmxflhlila{ }tmh xl khmexk{ pktg ke oe ozzikdoxkle%]ehmptxoehkea pktg) kedi}hkea xfm smdxlpt l oxxodg) xfm zpl`o`kikx{ l oxxodg oeh xfmzlxmexkoi kbzodx kt o dlpemptxlem l tmd}pm ozzikdoxkle hmsmilzbmex% Xfm o`kikx{ xl

    zpklpkxk~m pktg meo`imt xfm hmsmilzmpt xl ld}t xfmkp mlpxt le dlexplit xfox boxxmp bltx%Bkdpltlx fot hmsmilzmh xl bmxflhlilakmt xl kbzimbmex xfpmox blhmikea% Xfm ptx ktTXPKHM fkdf kt o bmxflh lp dfopodxmpk~kea gele xfpmoxt% Xfkt odple{b txoeht lp>

    Bkdpltlx fot hmsmilzmh o tmdleh bmxflhlila{ gele `{ xfm odple{b HPMOH fkdfkt }tmh xl dpmoxm o pktg poxkea xfox doe `m }tmh xl zpklpkxk~m pktg>

    Xfmpm opm lxfmp pobmlpgt lp xfpmox blhmikea7 }pxfmp pmskm l xfmtm tfl}ih zplskhmtlbm a}khmikemt le kbzimbmexkea xfkt zpldmtt lp {l}p emvx ozzikdoxkle%

    HMSMILZBMEX ZFOTM

    Dlhkea oeh Xmtxkea TxoehophtKe tmd}pm THID xpohkxkleoi dlhkea oeh xmtxkea txoehopht opm mvzoehmh xl kedi}hm tmd}pkx{dletkhmpoxklet% Tmd}pm dlhkea txoehopht odpltt oe mexmpzpktm bkekbk~m xfm pktg xfox ohmsmilzmp kii kexplh}dm o tmd}pkx{ s}iempo`kikx{ kexl xfm t{txmb xfox bo{ lp bo{ elx m

    Tzllckea Khmexkx{

    Xobzmpkea Qkxf Hoxo

    Pmz}hkoxkle

    Keclpboxkle Hktdilt}pm

    Hmekoi Lc Tmpskdm

    Mimsoxkle Lc Zpkskimam

    Hoboam Zlxmexkoi

    Pmzplh}dk`kikx{

    Mvzilkxo`kikx{

    Occmdxmh ]tmpt

    Hktdlsmpo`kikx{

    oam 1 y qqq%pmhtzke%dlb 0::; y Qfkxm

  • 8/8/2019 What Executives Need to Know About Web Application Development Security - Redspin Information Security

    9/13

    khmexkmh ke xfm ioxmp Qm` Ozzikdoxkle Tmd}pkx{ Ottmttbmex zfotm l xfm zplnmdx% Tmd}pmxmtxkea txoehopht met}pm xfox xfm _O xmob kedlpzlpoxmt bkt"}tm dotmt oeh lxfmp tzmdkdtmd}pkx{ tdmeopklt kexl xmtxkea%

    Txoxkd Oeoi{tktTxoxkd oeoi{tkt pmmpt xl o}xlboxmh dlhm oeoi{tkt xllit xfox hmxmdx tmd}pkx{ s}iempo`kikxkmt%Xfkt kt mttmexkoii{ o tl}pdm dlhm pmskm xfox kt o}xlboxmh oeh doe `m zplskhmh xlhmsmilzmpt tl xfm{ doe zmpklhkdoii{ tdoe xfmkp dlhm ot xfm{ opm hmsmilzkea mox}pmt oehfmizt zplskhm emop pmoi"xkbm mmh`odg le dlhkea mpplpt%

    Tl}pdm Dlhm PmskmO xfkph"zopx{ pmskm) mkxfmp { o zmmp kxfke xfm lpaoek~oxkle lp oelxfmp dlbzoe{) fmiztmet}pm xfox dlhkea txoehopht opm bmx oeh xfox xfmkp dlhm hlmt elx kedi}hm tmd}pkx{s}iempo`kikxkmt% Qfme tl}pdm dlhm pmskm kt kedi}hmh ot o bkimtxlem ke xfm hmsmilzbmexzioe) kx pmkelpdmt xl xfm xmob xfox tmd}pm dlhkea zpodxkdmt opm kbzlpxoex oeh soi}mhfkafi{ xfpl}afl}x xfm `}tkemtt }ekx%

    ]ekx Zmemxpoxkle XmtxkeaXfkt kt o `}kih imsmi Qm` Ozzikdoxkle Tmd}pkx{ Ottmttbmex% Ke m` hmsmilzbmex) xfmozzikdoxkle kt x{zkdoii{ kedlpzlpoxmh kexl o m` tmpsmp lp m` ozzikdoxkle pobmlpgt}df xfox ox sopkl}t zfotmt ke hmsmilzbmex xfm tl}pdm dlhm doe `m `}kix tl o p}eekeaozzikdoxkle &kxf ikbkxmh mox}pmt+ doe `m xmtxmh% ]ekx zmemxpoxkle xmtxkea ld}tmt letzmdkd mox}pmt lp zopxt l xfm dlhm `otm xl dozx}pm zlxmexkoi tmd}pkx{ s}iempo`kikxkmt

    fkim xfm ozzikdoxkle kt txkii ke hmsmilzbmex% Xfm khmo kt xl zplskhm mmh`odg xl xfmhmsmilzmpt fkim xfm{ opm txkii ke hmsmilzbmex oeh xmtxkea blhm) poxfmp xfoe okxkea }exkiioxmp fme xfm{ bo{ fosm blsmh lexl lxfmp zplnmdxt%

    HMZIL[BMEX ZFOTM

    Meskplebmex FophmekeaXfkt xotg kedi}hmt oii xfm txmzt emmhmh xl dpmoxm o tmd}pm meskplebmex ke fkdf oeozzikdoxkle kt fltxmh% Clp mvobzim) pl`}tx tl}pdm dlhm hlmt elx pmh}dm xfm lsmpoiitmd}pkx{ pktg b}df k lem l xfm tmpsmpt xfox kx p}et le kt dlea}pmh kxf o hmo}ix zottlphxfox doe `m a}mttmh `{ oe oxxodgmp% Dlbzlemext l meskplebmexoi fophmekea kedi}hmtmd}pkea oe{ tmpsmpt xfox fltx xfm ozzikdoxkle oeh hoxo`otmt }tmh ke xfm zplh}dxkle

    meskplebmex) }kihkea o tmd}pm emxlpg meskplebmex t}ppl}ehkea xfm t{txmb oeh met}pkeaxfox oii xfm emdmttop{ zf{tkdoi dlexplit opm ke ziodm%

    Ozzikdoxkle Zmemxpoxkle XmtxkeaXfkt keslismt dleh}dxkea o Qm` Ozzikdoxkle Tmd}pkx{ Ottmttbmex oaoketx xfm eoiozzikdoxkle `mlpm kx almt kexl zplh}dxkle% Xfkt kt xfm lem txmz xfox kt lxme kedi}hmhmsme ke ele"tmd}pm"THID hmsmilzbmex tflzt% Qfme kbzimbmexkea xfkt zfotm ke xfmdlexmvx l o tmd}pm hmsmilzbmex zpldmtt xfm e}b`mp l s}iempo`kikxkmt khmexkmh ktpmh}dmh tkaekdoexi{ &k%m% {l} eh mmp t}pzpktmt+% Ke tmd}pm THID) xfkt zfotm tmpsmtblpm ot o eoi tmd}pkx{ pmskm bkimtxlem poxfmp xfoe o xmtx xfox kii ikgmi{ fosm xl `mdlbzimxmh b}ixkzim xkbmt xl soikhoxm xfm pmbmhkoxkle l o tkaekdoex e}b`mp l tmd}pkx{s}iempo`kikxkmt%

    Ozzikdoxkle S}iempo`kikx{ Zioe oeh Smehlp S}iempo`kikx{ Zioe

    O s}iempo`kikx{ zioe pmmpt xl xfm hld}bmexmh zpldmtt kedlpzlpoxmh kexl tmd}pm THIDxl ohhpmtt xfm kemskxo`im tdmeopkl xfox o s}iempo`kikx{ kii `m khmexkmh ke xfm t{txmb%Xfm zioe tfl}ih oetmp xfmtm x{zmt l q}mtxklet> fl kii blekxlp xfm s}iempo`kikx{hoxo`otmt lp em s}iempo`kikxkmt< Qfl tfl}ih xfm{ elxk{< Fl tlle tfl}ih xfm ktt}m`m ohhpmttmh< Xfm ozzikdoxkle s}iempo`kikx{ zioe pmmpt xl s}iempo`kikxkmt khmexkmhtzmdkdoii{ kxf xfm d}txlb dlhm hmsmilzmh lp o d}txlb ozzikdoxkle) fkim xfm smehlps}iempo`kikx{ zioe ohhpmttmt s}iempo`kikxkmt l}eh kxfke xfm smehlp ozzikdoxklet) t}df otxfm ozzikdoxkle tmpsmp pobmlpg lp xfm tmpsmp lzmpoxkea t{txmbt%

    Kedkhmex Pmtzletm ZioeQfkim kx kt dlbblei{ oddmzxmh xfox o tmd}pm hmsmilzbmex zpldmtt kbzplsmt xfm tmd}pkx{l ozzikdoxklet oeh bkekbk~mt xfm lsmpoii pktg l o tmd}pkx{ kedkhmex) kx kt oitl khmi{oapmmh }zle xfox m` ozzikdoxklet kii emsmp `m dlbzimxmi{ pmm l pktg% Foskea oe

    oam 6 y qqq%pmhtzke%dlb 0::; y Qfkxm

  • 8/8/2019 What Executives Need to Know About Web Application Development Security - Redspin Information Security

    10/13

    Cka}pm 0 dfopodxmpk~mt fl hmsmilzbmexdltx oeh pktg opm kbzodxmh `{ blskeatmd}pkx{ mopikmp st% ioxmp ke xfm hmsmilzbmexzpldmtt%

    Ohhpmttkea Tmd}pkx{ Mopi{Tmd}pkx{ kexmapoxmh mopi{ {kmiht o blpmpl`}tx ozzikdoxkle xfox kt amempoii{dletkhmpmh xl bkekbk~m pktg% Oitl elxmxfox) fkim xfmpm kt o dltx ottldkoxmhkxf xfmtm tmd}pkx{ xotgt) xfmtm doe `mzioeemh kexl xfm zpldmtt oeh `}hamxmhlp xfm{ opm kexmapoxmh oeh mvzmdxmh%

    kedkhmex pmtzletm zioe ke ziodm `mlpm oe{ kedkhmex ldd}pt kii oiil xfm txogmflihmptxl dletkhmp oe odxkle zioe kxfl}x xfm zpmtt}pm oeh xkbm dletxpokext x{zkdoi l kedkhmexdpktkt boeoambmex%

    Tmd}pkx{ Pmq}kpmbmextXfkt pmmpt xl xfm tobm pmq}kpmbmext hktd}ttmh ke xfm ptx zfotm l hmsmilzbmex% H}pkeaxfkt zfotm xfmpm b}tx `m oe lealkea zpldmtt xl dozx}pm em tmd}pkx{ pmq}kpmbmext otxfm{ mbmpam% Qfmxfmp d}txlbmp hpksme lp h}m xl em pma}ioxkle) xfmtm em pmq}kpmbmextb}tx `m dlbb}ekdoxmh xl xfm emdmttop{ txogmflihmpt kxfke o zplnmdx%

    @}tkemtt Kbzodx lc Ohhpmttkea Tmd}pkx{ Mopi{Ohhpmttkea Tmd}pkx{ Ioxm@mdo}tm tmd}pkx{ cot dlhmh kexloe ozzikdoxkle mopi{ ke xfm zpldmtt)amempoii{ pmt}ix ke o imtt tmd}pmozzikdoxkle) kx kt zpmxx{ kex}kxksm xfoxhmio{kea tmd}pkx{ dletkhmpoxklet }exkiioxm ke xfm zpldmtt dletxkx}xmt fkafmp pktg%

    Qfox kt imtt mskhmex) kt xfox xfkt oitlpmt}ixt ke }eoexkdkzoxmh dltxt% Ox `mtx)xfmtm dltxt opm h}m xl ohhkxkleoi dlhkeaoeh _O d{dimt xfox pmt}ix plb foskea xfmQm` Ozzikdoxkle Tmd}pkx{ Ottmttbmexzplh}dm ehkeat xfox b}tx `m vmh`mlpm pmimotm% Ox lptx) xfm mvxpmbmi{fkaf dltx l o tmd}pkx{ `pmodf%

    Cka}pm 0%

    @}tkemtt Kbzodx

    lc Ohhpmttkea

    Tmd}pkx{ Mopi{

    oam ; y qqq%pmhtzke%dlb 0::; y Qfkxm

  • 8/8/2019 What Executives Need to Know About Web Application Development Security - Redspin Information Security

    11/13

    Tmd}pm THID Tmic Ottmttbmex "Fl tmd}pm kt b{ d}ppmex

    hmsmilzbmex zpldmtt

  • 8/8/2019 What Executives Need to Know About Web Application Development Security - Redspin Information Security

    12/13

    L dl}ptm boe{ lpaoek~oxklet mkxfmp hlex fosm oe mvktxkea tmd}pm THID lp xfm{ fosmo zlpxlikl l imaod{ ozzikdoxklet kefmpkxmh plb lxfmp `}tkemtt }ekxt lp odq}ktkxklet)lp xfm{ zpm"hoxm tmd}pm THID% Ke oe{ msmex) xfmtm ozzikdoxklet doe `m bkapoxmh xl otmd}pm THID% Flmsmp) `mdo}tm xfltm ozzikdoxklet bo{ mb`lh{ tkaekdoex pktg xl

    xfm `}tkemtt ke xfox ox oe{ xkbm xfm{ dl}ih `m dlbzplbktmh) o ld}tmh ozzplodf xlbkekbk~kea pktg kt mttmexkoi% Xfm liilkea sm txmzt tfl}ih `m dletkhmpmh kbbmhkoxmi{lp imaod{ ozzikdoxklet%

    ?% Mh}doxkle) Dlbb}ekdoxkle # Boeoambmex DlbbkxbmexBoeoambmex dlbbkxbmex kt blpm xfoe o txmz l dl}ptm7 kxt o d}ix}pm7 kxt o dlbbkxbmexxl }ehmptxoehkea xfm blhmpe xfpmox ioehtdozm t}df xfox tmd}pkx{ kt zpklpkxk~mh% Qkxfboeoambmex dlbbkxbmex dlbmt mh}doxkle7 bltx tmd}pkx{ `mtx zpodxkdmt) kedi}hkea xfmtxmzt keslismh ke tmd}pm THID opm okpi{ kex}kxksm ledm xfm eox}pm l tmd}pkx{ pktg kt}ehmptxllh% Kxt o `kx l o fox dobm ptx xfm dfkdgme lp xfm maa q}mtxkle fme kxdlbmt xl boeoambmex dlbbkxbmex oeh mh}doxkle ot modf lem xmeht xl liil xfmlxfmp) flmsmp) `lxf l xfmtm opm dpkxkdoi dlbzlemext xl `}kih kexl oe lpaoek~oxkle%Qkxf xfmtm xl dlbzlemext ke ziodm dlbb}ekdoxkle xfpl}afl}x oe lpaoek~oxkle kt oeox}poi zplapmttkle k boeoambmex txoxmt xfox kx }ehmptxoeht oeh pmtzmdxt xfm emmh lptmd}pkx{) kx doe `mdlbm o zpklpkx{% Oeh kxf dlbb}ekdoxkle dlbmt xfm emmh lp }pxfmpmh}doxkle tzmdkd xl xfm zopxkmt keslismh lp mvobzim) fmpm zplh}dx boeoampt bo{emmh fkaf"imsmi tmd}pkx{ xpokekea) hmsmilzmpt bo{ emmh tzmdkd tmd}pm dlhkea diottmt%

    0% Qm` Ozzikdoxkle Tmd}pkx{ OttmttbmexXfkt ottmttbmex kt o tzmdkd xotg ke tmd}pm THID% Kx keslismt oe l`nmdxksm xfkph"zopx{zmemxpoxkle xmtx l xfm ozzikdoxkle xl khmexk{ tmd}pkx{ s}iempo`kikxkmt% Qfkim hlkea xfkttxmz fme el lxfmp tmd}pm THID dlbzlemext opm ke ziodm bo{ {kmih o tkaekdoexe}b`mp l ehkeat xfox emmh xl `m ohhpmttmh) xfm zpldmtt lxme }edlsmpt tfl"txlzzkeadpkxkdoi s}iempo`kikxkmt xfox emmh xl `m ohhpmttmh kbbmhkoxmi{% K elxfkea mitm fot `mmehlem xl ohhpmtt tmd}pkx{) xfkt kt tlbmxfkea xfox tfl}ih `m dletkhmpmh%

    4% Qm` Ozzikdoxkle Pktg OttmttbmexHlkea o pktg ottmttbmex l {l}p m` ozzikdoxkle keslismt o tdoimh `odg smptkle lo e}b`mp l txmzt l xfm tmd}pm THID ot o tkeaim dlb`kemh hmiksmpo`im% Xfm aloil xfm pktg ottmttbmex kt xl q}kdgi{ ao}am xfm eox}pm oeh tmsmpkx{ l xfm tmd}pkx{ pktgl oe ozzikdoxkle% L}x l xfkt zpldmtt {kmiht xfm l`skl}t emvx txmzt xfox tfl}ih `mohhpmttmh xl tmd}pm xfm ozzikdoxkle% @mdo}tm modf ozzikdoxkle kt hkmpmex) xfm tmd}pkx{dletkhmpoxklet lp modf ozzikdoxkle sop{ tkaekdoexi{% Clp mvobzim) o z}`ikdi{"odkeaozzikdoxkle fkdf txlpmt bkiiklet l fmoixfdopm pmdlpht l}ih fosm hkmpmex tmd}pkx{pmq}kpmbmext xfoe oe kexpoemx }tmh lp xmob xpokekea% O m` ozzikdoxkle pktg ottmttbmexkeslismt xfpmox blhmikea) oxxodg t}podm oeoi{tkt) ozzikdoxkle dlbzimvkx{ q}oexkdoxkle)tmd}pkx{ opdfkxmdx}pm pmskm oeh meskplebmex oeoi{tkt% Xfm aloi kt xl q}kdgi{ khmexk{ pktgoeh doe x{zkdoii{ `m dlbzimxmh ke lem xl sm ho{t%

    8% Qm` Ozzikdoxkle Zlpxclikl Oeoi{tktO m` ozzikdoxkle zlpxlikl oeoi{tkt kt o dpltt"mexmpzpktm pktg ottmttbmex% Xfm aloi kt xl

    q}kdgi{ khmexk{ m` ozzikdoxklet xfox opm ox"pktg l o fkaf kbzodx tmd}pkx{ kedkhmex t}dfxfox xfm{ doe `m zpklpkxk~mh lp ohhkxkleoi tmd}pkx{ pmskm% Xfkt kt o apmox ptx txmz lpxfltm lpaoek~oxklet kxf o sopkmx{ l imaod{ m` ozzikdoxklet%

    Cl}p Txmzt xl Kbbmhkoxmi{ Kbzplsm xfmTmd}pkx{ lc [l}p Ozzikdoxklet

    oam ?? y qqq%pmhtzke%dlb 0::; y Qfkxm

  • 8/8/2019 What Executives Need to Know About Web Application Development Security - Redspin Information Security

    13/13

    Pmhtzke hmiksmpt xfm fkafmtx q}oikx{ Kelpboxkle Tmd}pkx{ Ottmttbmext xfpl}af xmdfekdoimvzmpxktm) }tkemtt od}bme oeh l`nmdxkskx{% Pmhtzke d}txlbmpt kedi}hm imohkea dlbzoekmtke opmot t}df ot fmoixfdopm) eoedkoi tmpskdmt oeh flxmit) dotkelt oeh pmtlpxt ot mii otpmxokimpt oeh xmdfelila{ zplskhmpt% Tlbm l xfm iopamtx dlbb}ekdoxklet zplskhmpt oehdlbbmpdkoi oegt pmi{ }zle Pmhtzke xl zplskhm oe mmdxksm xmdfekdoi tli}xkle xokilpmh xlxfmkp `}tkemtt dlexmvx) oiilkea xfmb xl pmh}dm pktg) bokexoke dlbzikoedm oeh kedpmotmxfm soi}m l xfmkp `}tkemtt }ekx oeh KX zlpxliklt%Zmemxpoxkle Xmtxkea

    Qfkim el ozzikdoxkle doe `m dlbzimxmi{ tmd}pm) xfm dletmet}t oblea xfm tmd}pkx{oeh hmsmilzbmex dlbb}ekx{ kt xfox xfltm ozzikdoxklet hmsmilzmh kxf o zpldmtt xfoxkexmapoxmt tmd}pkx{ mopi{ le oeh xfpl}afl}x xfm hmsmilzbmex zpldmtt tkaekdoexi{ pmh}dmttmd}pkx{ pktg &fkim ikbkxkea t}pzpktmt+% Opbmh kxf oe }ehmptxoehkea l xfm tmd}pm THIDoeh kxt `otkd dlbzlemext KX hmdktkle bogmpt tfl}ih `m o`im xl dlbb}ekdoxm `lxf xfmemmh lp tmd}pkx{ oeh xfm `memxt l tmd}pm THID%

    Dledi}tkle

    O`l}x Pmhtzke%pmhtzke%dlb

    http://www.redspin.com/http://www.redspin.com/http://www.redspin.com/