Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • SEARCH
  • Home
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 454055
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: May 12, 20262026-05-12T22:13:58+00:00 2026-05-12T22:13:58+00:00

In your experience, what have you found, worked on, or encountered in terms of

  • 0

In your experience, what have you found, worked on, or encountered in terms of site vulnerabilities? And what actions did you take to mitigate these issues?

This may include XSS (cross site scripting), SQL Injection attacks, plain old DDOS or phishing attempts on your site’s customers. Only yesterday I came across an entire section of Firefox tools for auditing sites and their potential for various vulnerabilities.

Looking to expand my knowledge in this area for a role, so more information to read or learn is always good – solid links appreciated too! And war stories of the worst you’ve found or scariest hole you’ve seen – learning from experience is the best way sometimes!

  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-05-12T22:13:58+00:00Added an answer on May 12, 2026 at 10:13 pm

    I’ve done security review, white-box and black-box, for dozens (hundreds?) of applications and sites.

    1. XSS and SQL injection get a lot of press, but know what I find the most common security flaw to be? Leaving debug and test functionality in production code. Either by tampering with POST parameters (isDebug=True) or via spidering a site and finding leftover pages, these are the worst mistakes I see regarding security. If you’re including test/debug code, put it in a separate code branch, or at least prepare a checklist for removal prior to launch.

    2. The next most common vulnerability I’ve seen is simply the ability to bypass security mechanisms by grabbing a URL from the page source. The technical name is ‘Forceful Navigation’ or ‘Forced Browsing’ This is something anyone who can read HTML can do, yet I’m surprised by the variety of applications vulnerable. Reviewing a ticket-purchasing site yesterday, I was able to buy tickets for sold-out shows using this method. On previous sites, I was able to skip paying altogether (many, many Paypal sites pass the “purchase complete” URL to paypal via POST parameters – yoink!). You need some sort of back-end statefulness or check to ensure completion, payment, availability, accuracy, etc.

    3. To be frank, I usually let tools like AppScan, BURP proxy, WebScarab, Fortify, FindBugs, or YASCA (depending on budget and source code accessibility) find XSS and SQL injection attacks for me. I’ll try the simple stuff on my own, look for obvious holes, but there’s too many known combinations to try yourself. I keep a small collection of scripts and test cases for more advanced or recently discovered flaws.

    I’m going to stop at 3, because I really could go on all day, I’m losing focus from your question, and nobody wants to read a wall of text.

    Some resources for new and seasoned web security gurus:
    (ARGH. I can’t officially post links yet. Copy/paste. Sorry)

    The Open Web Application Security Project (OWASP)

    http://www.owasp.org/

    Web Security Testing Cookbook

    This book is written for auditors, testers, and less for developers. Which is pretty unusual for an O’Reilly book.

    websecuritytesting.com

    Vulnerability Categorization by Fortify

    http://www.fortify.com/vulncat/

    Common Weakness Enumeration (warning: extensive)

    nvd.nist.gov/cwe.cfm

    Common Attack Pattern Enumeration and Classification (warning: even more extensive)

    capec.mitre.org/

    Google’s Web Security Tutorials

    (rather weak)

    code.google.com/edu/security/index.html

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

I have a little experience with WCF and would like to get your opinion/suggestion
I have had experiences of Reverse engineering and people taking access of your Database
From your experience, what is the most accurate open-source Optical Character Recognition (OCR) library/software
I really want to know your experience at working with ADO.Net datasets (calling stored
I just want to ask for your experience. I'm designing a public website, using
In windows 8 consumer preview you can personalize your experience, including setting a 'background
I know, I am asking stupid question but your experience will help me to
With your help I could take the input from a text file (input.txt) where
I believe several of us have already worked on a project where not only
Ok, everybody get in your wayback machine. I need to have a phone dial

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.