××¢×§×××Ŗ פרה×× ××”×× ××××§××Ŗ ××¢××× ×××××”×” ×¢× ××ר×× ×××××§××Ŗ ×©× OWASP ××××× ×©× 0xicf
×צ"× ×××”×× ×תר××× ×××¤×©× ××¢×ר××Ŗ: - 61 ×××§×× ×××××§×× ××§×××ר×××Ŗ ש×ש×××× ××××× ××Ŗ ×××××Ŗ ××פ××קצ×× .
× ××Ŗ× ×××ר×× ×× ××Ŗ ××§××ׄ ×פ×ר×× XLS ×פ××Ø× ××××.
×××”××£ ××××¢:
1.
צ×צ××
××× ××פשר ×צ××Ŗ ××××¢ ××××¢ קר××× ×¢× ×Ø×××× ××ער××Ŗ
××Ø× ××¢× × HTTP ×× HTTP
ERRORS ,××××¢ ××××× - ×©× ×שרת , ××Ŗ××××Ŗ IP ×¤× ×××××Ŗ, ×רהת ×ער××Ŗ ×פע×× ,×”×× ××רהת ××פ××קצ××,×”××\×רהת ××”× ×× ×Ŗ×× ×× ×××¤×©×Ø× ××Ŗ××§×£ ××× × ××××§×× ××תקפ×.
××ר ××× ×¤×..
http://technet.microsoft.com/en-us/security/cc242650.aspx = IIS
APACHE:
Open your httpd.conf file using text editor such as vi:
vi httpd.conf
Append/modify config directive as follows:
ServerSignature Off
ServerTokens Prod
Save and close the file. Restart Apache web server:
# /etc/init.d/httpd restart
2.
ש×××××Ŗ
×× ×©××××Ŗ ×שרת ××פ××קצ×× ×× ×××§×× ×ש×××××Ŗ ×ער××Ŗ ××××× ×× ×× ×××× ××××¢.
4.
×ש ×××××
××¤× ×פ××קצ×× ×Ø××ש×× ××§××ׄ robot.txt ( ×× ××¢×Ŗ הר××§× ×××× ×××§×”)
×× ××¤× ×××©× ×§×Ø××××× ×××× ×פ×× ××שת ADMIN ×××
×××××× ××§××ׄ ××.
××××× http://blog.imperva.com./robots.txt
× ×××× ×§×× ×¤×××רצ××:
5.
×ש
×××Ŗ×§×× ×××§×× ××פשר ××Ŗ ×× ×××× ××××××
×¢××ר ×× ××ער×××Ŗ – שרת×× ,×פ××קצ×××Ŗ , ××”×× × ×Ŗ×× ×× ×××
6.
×ש ××××
××Ŗ ×× ×©××××Ŗ ××××©× × HTTP ×××¢× GET × POST (head,options,put
….) ××××× ××× ×× ×ש×××ש
7.
×ש ×××”××
×××©× ××× ×ש×× ×× "צ×××ר×" non public ××××××Ŗ: ×תר×× ××©×Ø×Ŗ× ×××××,×©×Ø×Ŗ× TEST ,STAGE ,××Ŗ×Ø× DEMO, QA ×××
9.
×ש ×××”×ר
×× ×ש××× × ×שת×ש ×ר×רת ×××× DEFAULTS ×××שרת,××פ××קצ×× ×××”×× ×× ×Ŗ×× ××
10. ×ש ×ש××× ×××”× × ××פ×× × HTML e.g. autocomplete,
cache-control, pragma ××× ××¢×Ŗ ש××רת ××××¢ ר××ש ×CACH ( ×”×”××××Ŗ session ×××)
If you want to remove the warning entirely, you can use JavaScript to apply the attribute to browsers that support it (IE and Firfox are the important browsers) using someForm.setAttribute( "autocomplete", "off" ); someFormElm.setAttribute( "autocomplete", "off" );
12.
××××× SSL renegotiation – ××× ××¢×Ŗ ×תקפ××Ŗ ×× ××¢×Ŗ ש×ר××Ŗ ×MITM .
××× ××××§× ×פ×××¢××Ŗ ××תר
IIS versions 6 and above are NOT affected by the renegotiation DoS attack since http.sys (http driver on Windows Server) disallows client initiated renegotiation in SSL and sends a TCP RST anytime a client attempts a renegotiation.
13.
צ××צ×× ××××§×× ×××× ×××Ŗ ×רש××Ŗ ×××©× ××הפר ×××××× ×× ( cross domain policy ) (for Flash
crossdomain.xml and for SilverLight
clientaccesspolicy.xml) , ××××× ×רש×× ××רפת × * .
קר××× × ×הפת
××××××Ŗ – authentication
14. ש×××ש ××”×”××××Ŗ ×××§××Ŗ ×××ר××××Ŗ ×××× ×× ×ר××Ŗ × ADMIN ××× ×ר××Ŗ ×××§××
16. ש×××ש × HTTPS SSL ×¢××ר ×× ×Ŗ×¢××רת ××××¢ קר××× ×××× ×”×”××××Ŗ, ×ר×××”× ×שר×× ,××××¢ ××ש×
×××
17. ×× ××××§××Ŗ ×××××××Ŗ ×××רש×××Ŗ ××Ŗ××¦×¢× ××¦× ×שרת SERVER
SIDE
19. ×ש ××פ××Ŗ ×¢× ××שת×ש×× ×©×× ××
××”××”×× ×ר×ש×× ××Ŗ שק×××× ×××צע×× ×××× ×××× ×× ××” ×× ××”.
20. ×× ×¤×¢××××Ŗ קר××××Ŗ ××ער××Ŗ תש×ר ××××× ((LOG ×× ×ר××Ŗ ×שרת ××× ×ר××Ŗ
××פ××קצ××.
21. ×ש ×ש××ר ××× ×©× ×× ××××××Ŗ ×××× ××× ××××××Ŗ ש×××× (successful and unsuccessful login).
22. ×ש ××צ×× ××××¢× ×'× ×Ø××Ŗ ×¢××ר ×ש××× ××××××Ŗ: Username and/or Password
is wrong
Session management
25. ×ש ×××צר ×××× ×× ×¢×Ø×× ××ש ( session id ) ×¢××ר ×× ×× ××”× ××ער××Ŗ +×× ××”× ×××ש ××× ××××
××Ŗ ××××× ×××ר ××צ××¢ ×צ××× ×××ער××Ŗ.
27. ×¢×××××Ŗ ( COOKIES) ××ש×ש××Ŗ ×××××§×Ŗ SESSION ID – ××××××× ××××××× ×ש×××ש ××××Ŗ×
×תרDOMIAN ××××.
29. ×ש ×××¤× ××Ŗ ××Ŗ ××שת×ש ××Ø× ××£ 302 ×××£
×¤× ××× ×××ר ××××××Ŗ ××צ×××Ŗ.
30. ×ש ××פשר ×פשר××Ŗ ×צ×××( LOG OUT) ××× ××£ ××תר.
×רש×××Ŗ,××ש×ר××
31. ×ש ××§××Ŗ ××ש××× ×××× ××¢ ש×× ×× ×ער×× ×¤×Ø××ר×× ××קש××Ŗ HTTP GET × POST ×¢"× ××Ŗ××§×£ ×¢"× ××צ××¢ ×××××Ŗ ××§×× ×× ××¦× ×××§×× ×××¢×קר
××¦× ×שרת
32. ×ש ×××××× ××Ŗ ×רש×××Ŗ ×שת×ש ××ער××Ŗ ש×ר×ׄ ××Ŗ ××פ××קצ×× ××¦× ×שרת ××Ŗ×§××× ××ש××× ××פ××קצ×× ××××.
33. ×ש ×××××× ××Ŗ ××שת ×שת×ש ××ער××Ŗ ×× ×רק ×××××××Ŗ ×ר×××× ××××Ŗ ×× ×××”×
×× ×Ŗ×× ×× DB.
34. ×ש ×××××× ×××©× × DB רק ×××Ŗ×××Ŗ ×IP ×©× ××פ××קצ×× ××¢"× ×©× ×שת×ש ××××× ×©× ××ער××Ŗ.
35. ×ש ××צע ×”×× × ×ר×× ××צ×× ××××× ××Ŗ ×©× ×ש××× ×ער××Ŗ קר×××× ××× ××¢×Ŗ race contrition .
36. ×ש ×××××× ××שת×ש×× ×תפק×××× ×××©× ××× ×פ××קצ××Ŗ × ×××ר ××××”××£
×”×××××”××ר××Ŗ ××××©× ( ×× ×××Ŗ×§× ×).
37. ×ש ×××××× ××שת×ש×× ×תפק×××× – ×××©× ××× ×ש×× ×§×Ø××× ××ער××Ŗ
38. ××××× ×רש×××Ŗ ××××× ××× ×× ××Ŗ× ×¢××ר ×שת×ש שע×× ××Ŗ ××××Ø× ×× ×¢×ר תפק××
×××.
×××××§× ×¢×”×§××Ŗ - Business
Logic
39. ×ש ××ר×ש ×××שת×ש ××Ŗ ××”×”×× ×× ×××××Ŗ ××× ×¤×¢× ×©× ×רש ש×× ×× ×× ×××”×¤× ×©×
פ×× ×§××× ×××××Ŗ ××תר.
40. ××Ŗ×××× ×©×××ר ×”××”×× ,×××
×ש××× ××Ŗ ××”××”×× ××××× ×× ××××¦×¢× ××ר – ×××§×× ×××Ŗ ×ש ×ש××× ××× ×§ ××××× ×××× ×××××
×××××× ×××פ××” ×”××”××.
41. ×ש ××שת×ש ×ש××××Ŗ ×”×××××Ŗ ×× ×××¦×¢× ×××× ××Ŗ×××× ××××ר ×”××”××
42. ××× ××Ŗ×Ŗ ש×××Ŗ ×§××× ×× ×××ש ×¢××ר הפר×××Ŗ ××פ×× ×§×Ø××××× ××תר (e.g. admin, administration).
43. ×××¢×ר ×××ר ××”×××××Ŗ × TEST QA ××× ××”×××××Ŗ × PROD – ×ש ××××× ×©×× ×××¢××Ø× ××§×ר××Ŗ
×× × ××צ×× (e.g. test codes, demo applications, backup
files) ×× ××”×£, ×ש
×××”×ר ×ער××Ŗ ××§×× ×××§×ר ××ש ××××× ×× × ×©×רת ש××××Ŗ ××××× ××Ŗ ××××ר ×××× ×××¢×ר.
44. ×ש ×××××§ ××¤×¢× ××¤×¢× ×× ×פ×× ×§×Ø×××××
××ער××Ŗ ADMIN ××× ×× × ×”×Ø×§××
×¢"× ×× ××¢× ××פ×ש GOOGLE BING ×××.
×××××Ŗ × ×Ŗ×× ×× – data
validation
45. ×ש ××××Ŗ ××Ŗ ×× ××§×××× ×××שת×ש×× ××¦× ×שרת,×ש ×××¢×××£ ש×××ש × ×Ø×©××××Ŗ
××× ××Ŗ ××שר ×רש××××Ŗ ש××ר××Ŗ White-lists should be preferred
for validation instead of black-lists.×ש ××§×× ×× ×§×× ××§×××× × ×¤×ׄ ××¤× × ××צ××¢
×××××§××Ŗ
46.
×× ×§××
××שת×ש ××שת×ש ××××§ ×פק××× ( ש××××Ŗ× × DB ×××) ×××¤×¢× ×Ø×§ ×××ר ××צ××¢ ××××§××Ŗ escaped and
validated
47.
ש×××ש
×××× ×××××××Ŗ ××× ××¢×Ŗ ×תקפת SQL INJECTION -Prepared statement, parameterized query, bind variables and whitelist
data
48. ×× ×§×× ××ש×שת×ש ××§××× ×××××§× ××ר×× ××Ŗ×× × ××¤× × ×©×××¦× ××××Ø× ×¢× ××”×
××שת×ש.
49.
×× ×§×× ×שת×ש ××ש×ש
×××ש×××× ××××××× ××××§ ×ער×× ××× ×××× ×××§×”××××
50. ×× ×§×× ×שת×ש ××שת×ש ××××©× ××§×צ×× ××¢××ר ××××§× ××”× ××צ××
51. ××Ŗ×××× ××¢×××Ŗ ×§××ׄ file upload – ××××§× – ש×,×××× ,×”×× , ××Ŗ×××
××§××ׄ ××¤× × ××Ŗ××××Ŗ ××Ŗ××××
52. ×§×× ×שת×ש ××ש×ש ×××צ××¢ ××¤× ×× ××ער××Ŗ REDIRECT – ××××§ ×××צע××Ŗ white list ××××Ŗ ×× ×× ×Ŗ ××× ××¢ ×תקפ××Ŗ פ×ש×× × prevent
phishing attacks (open redirect problem).
53. ×× ×§×× ×שת×ש ×¢××ר ש××××Ŗ××Ŗ LDAP – ××¢××ר ××××§××Ŗ
54. ×× ×§×× ×שת×ש ×¢××ר xpath - ××¢××ר ××××§××Ŗ
55. × ××§×× CR/LF characters ××§×× ××שת×ש ××× ××¢×Ŗ CRLF injection attack
56. ×ש ××××©× ×¤×Ŗ×Ø×× ××Ŗ ×¢××ר ×תקפ××Ŗ frame busting and
clickjacking
57. ×ש ××צע ××××§×Ŗ ×××ר××Ŗ ××¤× × ×¢××××Ŗ ××תר ×××ש ×××××ר
×× ××¢×Ŗ ש×ר××Ŗ – DOS ATTACKS
58. ×ש ××××©× ××צע×× ×××××× ×××Ø× ×× ××©× ( CAPTCH ×××) ××פה×× FORMS ××תר.
59. ×ש ××××©× ×× ×× ×× TIMEOUT ×¢××ר ××פש×× ××תר ×××× ××¢ ×”××× ××פ×ש ××¢×××”×× ×××× ××פ×ש * ×××
ש×ר××Ŗ× WEB – WEB SERVICES
60. ×ש ××××©× ×××× ××קצ×× ×¢××ר ××ש××Ŗ × WS ×××× ×××××××Ŗ SOAP,
Restful, XML-RPC ×××
61. ×ש ××צע INPUT VALIDATION ×××פ×× ×ער×× ××× ×××× ××§×”××××Ŗ ×©× ×¢×Ø××× ××× ××¢×Ŗ ×תקפ××Ŗ (e.g. external entity, a
billion laughs, XML bomb, etc