IT security in web development
In short: Web applications are reachable from the internet and are therefore a main target for attacks. Developers must avoid typical weaknesses from the start.
In more detail: The best-known risks are collected by the OWASP project in the “OWASP Top 10”. The most important countermeasures are well known and can be planned in.
In Depth
Common attacks and protection
| Attack | Protection |
|---|---|
| SQL injection ([[sqli | SQLi]]) |
| Cross-site scripting (XSS) | escape output, set a [[content-security-policy-(csp) |
| CSRF | SameSite cookies, anti-CSRF tokens |
| Broken login | store passwords only hashed ([[hashing |
| Open access | check permissions on the server for every request |
| Unsafe uploads | check type and content, limit size |
Basic rules
- Never trust input: always check on the server, not only in the browser.
- HTTPS everywhere with HSTS (certificates).
- Cookies:
HttpOnly,Secure,SameSite(cookies). - Security headers such as CSP, X-Frame-Options.
- Rate limiting and bot protection against abuse.
- Secrets (keys, passwords) never in code or repository, but in the environment.
- Keep dependencies up to date and scan for vulnerabilities.
- Error messages without internals, details only in the log.
- Minimal privileges for database users and services.
More on the principle: security by design, security by default.
See also: IT security, forms, sessions and security