01.07.2015 Views

OWASP测试指南

OWASP测试指南

OWASP测试指南

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

OWASP 测 试 指 南 v3.0<br />

OWASP-IG-006 Analysis of Error Codes Information Disclosure<br />

OWASP-CM-001<br />

SSL/TLS Testing (SSL Version,<br />

Algorithms, Key length,<br />

Digital Cert. Validity)<br />

SSL Weakness<br />

OWASP-CM-002 DB Listener Testing DB Listener weak<br />

OWASP-CM-003<br />

Infrastructure Configuration<br />

Infrastructure<br />

Management Testing<br />

Configuration<br />

management weakness<br />

OWASP-CM-004<br />

Application Configuration<br />

Application<br />

Management Testing<br />

Configuration<br />

配 置 管 理 测 试<br />

OWASP-CM-005<br />

Testing for File Extensions<br />

management weakness<br />

File extensions handling<br />

Handling<br />

OWASP-CM-006<br />

Old, backup and<br />

Old, backup and<br />

unreferenced files<br />

unreferenced files<br />

OWASP-CM-007<br />

Infrastructure and<br />

Access to Admin<br />

Application Admin<br />

interfaces<br />

Interfaces<br />

OWASP-CM-008<br />

Testing for HTTP Methods<br />

HTTP Methods enabled,<br />

and XST<br />

XST permitted, HTTP<br />

Verb<br />

OWASP-AT-001<br />

Credentials transport over<br />

Credentials transport<br />

an encrypted channel<br />

over an encrypted<br />

channel<br />

OWASP-AT-002<br />

Testing for user<br />

User enumeration<br />

认 证 测 试<br />

enumeration<br />

OWASP-AT-003<br />

Testing for Guessable<br />

Guessable user account<br />

(Dictionary) User Account<br />

OWASP-AT-004 Brute Force Testing Credentials Brute<br />

forcing<br />

49

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!