In January I predicted that there will be common functions that developers could use to develop more resilient web-applications. Seems that at OWASP there has been some progress in this area, they released an API for Java just a while ago. The site stated that similar APIs are already being planned/built for .NET and PHP.
I had no previous knowledge of this project, but cool to see that some people put effort in it. OWASP is quite respected, so this could mean wider adoption of the provided tools. I haven't looked at the ESAPI to see what kind of input validation it provides, which was my main point. Based on the powerpoint it offers all sorts of web-app related security functionalities.
www.liquidinfo.net - Security is a mindset
Proud member of Security Bloggers Network
February 24, 2009
Subscribe to:
Post Comments (Atom)
0 comments:
Post a Comment