NB: The key concept for this card is protection of administrative web interfaces such as Content Management System (CMS), database and server web control panels.
Michael can bypass the application to gain access to data because administrative tools or administrative interfaces are not secured adequately
Owasp ASVS (4.0): 1.4.3 ,1.4.5 ,4.3.1
Owasp SCP: 23,29,56,81,82,84,85,86,87,88,89,90
Owasp Appsensor:
Safecode:
ASVS V1.4 - Access Control Architectural Requirements
ASVS V4.3 - Other Access Control Considerations
Password Guessing/Brute Force Attacks
Session Hijacking (Man-in-the-Middle)
Loading comments 0%