Web Application Security Quiz

214 views
Skip to first unread message

Timo H

unread,
Jun 10, 2013, 7:22:23 AM6/10/13
to se...@googlegroups.com
Hello all,

it has been a bit silent here on the PHP Security Technical Group, so I thought to share a link you might find interesting.

I did set-up a small online quiz about web application security. Currently it has 15 questions ranging from simple, to more infrequent quirks and web application related principles (a few of the questions are directly PHP related).

My main point with the quiz was to raise awareness about these principles, quirks and problems (I don't think it is a "quiz" per-se, but more like an "educational tool").

http://timoh6.github.io/WebAppSecQuiz/

Any feedback much appreciated!

Timo


Chris Cornutt

unread,
Jun 10, 2013, 7:30:58 AM6/10/13
to se...@googlegroups.com
Pretty cool..I wish it provided more feedback on the correct/incorrect ones though - just the numbers if good but knowing the ones missed and a reminder of their text might be nice.

thanks for the work on this! off to a good start :)

-chris




Timo


--
You received this message because you are subscribed to the Google Groups "PHP Security Technical Group" group.
To unsubscribe from this group and stop receiving emails from it, send an email to sectg+un...@googlegroups.com.
For more options, visit https://groups.google.com/groups/opt_out.
 
 



--
Senior Editor
PHPDeveloper.org
ccor...@phpdeveloper.org
@enygma

Timo H

unread,
Jun 10, 2013, 7:45:01 AM6/10/13
to se...@googlegroups.com
I was thinking to write a blog post explaining the reasoning behind the answers. Not yet done thought. @ircmaxell also used that quiz on his Code Review for Security workshop, I need to ask if he had put his explanations about the correct answers on a "paper", so I could borrow that ;)

As a spoiler, I answered some of those question on the (now hidden, I think) Reddit netsec: http://www.reddit.com/r/netsec/comments/1g15jl/web_application_security_quiz_15_questions_about/

Thanks for the feedback!

Timo

Timo H

unread,
Jun 12, 2013, 7:12:43 AM6/12/13
to se...@googlegroups.com
I just added a page with answers and brief commentary:
http://timoh6.github.io/WebAppSecQuiz/answers.html


Timo

maanantai, 10. kesäkuuta 2013 14.30.58 UTC+3 Chris Cornutt kirjoitti:

Pádraic Brady

unread,
Jun 12, 2013, 7:55:43 AM6/12/13
to se...@googlegroups.com, se...@googlegroups.com
Hey!

Tried it out yesterday ;). It's a great idea if it can be rolled out large scale (or at least the question bank data). What are your intentions for its future development? 

Paddy

Pádraic Brady

Timo

unread,
Jun 12, 2013, 8:29:57 AM6/12/13
to se...@googlegroups.com
Hi,

and thanks for the feedback!

I'm open to all suggestions about the future development. For now, I see there is a room for more questions. But another matter that was suggested, was to separate the questions based on the "difficulty level". For now I see it is better to keep it as a single quiz (there is only 15 questions), but anything that can make the quiz better (in a sense it educates people), I'm open to hear. And of course, if you have some questions to be added on your mind, feel free to inform me :)

Timo


2013/6/12 Pádraic Brady <padrai...@gmail.com>
Reply all
Reply to author
Forward
0 new messages