Web application security article

46 views
Skip to first unread message

Donald McLean

unread,
Aug 28, 2015, 9:42:04 AM8/28/15
to liftweb
I saw this and I thought folks here might find it interesting.

I think that many, perhaps most of these are the responsibility of the app developer and not something that Lift can address directly - or am I wrong?

Donald

http://www.eweek.com/security/slideshows/top-10-common-application-attacks-to-avoid.html

Diego Medina

unread,
Sep 2, 2015, 7:57:03 PM9/2/15
to Lift
I agree, out of those included in that presentation, things like CSRF, XSS are things Lift protects you from, but things like redirect validation are best done at the application level.

--
--
Lift, the simply functional web framework: http://liftweb.net
Code: http://github.com/lift
Discussion: http://groups.google.com/group/liftweb
Stuck? Help us help you: https://www.assembla.com/wiki/show/liftweb/Posting_example_code

---
You received this message because you are subscribed to the Google Groups "Lift" group.
To unsubscribe from this group and stop receiving emails from it, send an email to liftweb+u...@googlegroups.com.
For more options, visit https://groups.google.com/d/optout.



--
Diego Medina
Lift/Scala consultant
di...@fmpwizard.com
http://blog.fmpwizard.com/
Reply all
Reply to author
Forward
0 new messages