11.07.2015 Views

EC-Council Certified Secure Programmer

EC-Council Certified Secure Programmer

EC-Council Certified Secure Programmer

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

• Solution for Session ID Protection• Error Reporting• Data Handling Errors• Security Sensitive PHP Functions:File Functions• Security Sensitive PHP Functions: ezmlm_hash• PHP Exploitso Forms and Datao Semantic URL Attackso File Upload Attackso Cross-Site Scripting (CSS/XSS)o Cross-Site Request Forgerieso Spoofed Form Submissionso Spoofed HTTP Requestso Sessions and Cookieso Cookie Thefto Exposed Session Datao Session Fixationo Session Hijacking• PHP Vulnerabilitieso Informational Vulnerabilitieso Common File Name Vulnerabilityo Revealed Source Code Vulnerabilityo Revealing Error Message Vulnerabilityo Sensitive Data in Web Root Vulnerabilityo Session File in Shared Server Vulnerabilityo Sensitive Data in Globally Readable File Vulnerabilityo Revealing HTML Comment VulnerabilityPage 21http://www.eccouncil.org<strong>EC</strong>-<strong>Council</strong>

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!