4 ms·
Do you have a write-up of your "list of 7 Deadly Web App Features" somewhere in the web? I don't see it in Matasano's blog or the googles, thanks.
by fduran 14y ago
Do you have a write-up of your "list of 7 Deadly Web App Features" somewhere in the web? I don't see it in Matasano's blog or the googles, thanks.
- tptacek 14y ago1. Password reset. 2. Email 3. Thick clients. 4. File upload. 5. File download. 6. Templating (as an app feature, not as a dev tool). 7. "Advanced Search". This list is a couple years old. We're going to start tying bug reports to functional areas in targets to get a better empirical list by the end of the year. I expect the new empirical list to be more boring and less useful, though.
- euroclydon 14y agoEmail? As in like sending emails?
- tptacek 14y agoWe take very hard looks at both inbound and outbound email functionality. Bunch of reasons: 1. Breaks out of the web security domain, requiring devs to think through and implement controls that compensate for things like sessions and access control. 2. New quoting domain creates opportunities for injection to leverage apps to send unexpected messages. 3. Often involves shelling out, with all the attendant risks of that. 4. Inbound mail has different input restrictions than web apps do, creating opportunities for submarined XSS or even SQLI. It's just a really common place where apps suddenly sprout unexpected moving parts, is what it boils down to.
- deleted 14y ago[deleted]