EMZETT.
Login

IT security in web development

In short: Web applications are reachable from the internet and are therefore a main target for attacks. Developers must avoid typical weaknesses from the start.

In more detail: The best-known risks are collected by the OWASP project in the “OWASP Top 10”. The most important countermeasures are well known and can be planned in.

In Depth

Common attacks and protection

AttackProtection
SQL injection ([[sqliSQLi]])
Cross-site scripting (XSS)escape output, set a [[content-security-policy-(csp)
CSRFSameSite cookies, anti-CSRF tokens
Broken loginstore passwords only hashed ([[hashing
Open accesscheck permissions on the server for every request
Unsafe uploadscheck type and content, limit size

Basic rules

  • Never trust input: always check on the server, not only in the browser.
  • HTTPS everywhere with HSTS (certificates).
  • Cookies: HttpOnly, Secure, SameSite (cookies).
  • Security headers such as CSP, X-Frame-Options.
  • Rate limiting and bot protection against abuse.
  • Secrets (keys, passwords) never in code or repository, but in the environment.
  • Keep dependencies up to date and scan for vulnerabilities.
  • Error messages without internals, details only in the log.
  • Minimal privileges for database users and services.

More on the principle: security by design, security by default.

See also: IT security, forms, sessions and security