Knowledgebase

Web Security: Everything That Matters, Briefly Print

  • webdevelopment, security, domainrenewal, ssl, database, password, performance, troubleshooting, renewal
  • 0

The summary.

THE COMMONEST SERIOUS FAULT IN CUSTOM APPLICATIONS

Checking authentication but not authorisation. A signed-in user changes an identifier and reaches another user's data.

Verify on every action that this user is entitled to this specific record. Hiding interface elements is not access control.

PARAMETERISE EVERY QUERY, WITHOUT EXCEPTION

And validate column or table names against a fixed list, since those cannot be parameterised.

ESCAPE FOR THE CONTEXT

Markup, attributes, addresses and scripts each require different escaping. Never trust data from your own database — it was once input.

Never write your own sanitising filter.

NEVER DISABLE CROSS-SITE REQUEST PROTECTION TO MAKE SOMETHING WORK

And never let a retrieval change state — a link or an image can trigger it.

FOR PASSWORDS, USE AN ALGORITHM DESIGNED FOR THEM

Deliberately slow. Never limit length or restrict characters, and reveal nothing about which part of a sign-in failed.

MONITOR CERTIFICATE EXPIRY INDEPENDENTLY

Automated renewal fails silently more often than expected.

THIRD-PARTY SCRIPTS CAN DO EVERYTHING YOUR OWN CAN

Including reading what users type. Minimise them and know what each does.


Was this answer helpful?
Back

Are you happy with your experience? Leave us a review on Trustpilot.


Trustpilot