OWASP(¿ª·ÅWebÈíÌ尲ȫÏîÄ¿- Open Web Application Security Project)ÊÇÒ»¸ö¿ª·ÅÉçȺ¡¢·ÇÓªÀûÐÔ×éÖ¯£¬Ä¿Ç°È«ÇòÓÐ82¸ö·Ö»á½üÍòÃû»áÔ±£¬ÆäÖ÷ҪĿ±êÊÇÑÐÒéÐÖú½â¾öWebÈíÌ尲ȫ֮±ê×¼¡¢¹¤¾ßÓë¼¼ÊõÎļþ£¬³¤ÆÚÖÂÁ¦ÓÚÐÖúÕþ¸®»òÆóÒµÁ˽Ⲣ¸ÄÉÆÍøÒ³Ó¦ÓóÌʽÓëÍøÒ³·þÎñµÄ°²È«ÐÔ¡£ÓÉÓÚÓ¦Ó÷¶Î§ÈÕ¹ã£¬ÍøÒ³Ó¦Óð²È«ÒѾÖð½¥µÄÊܵ½ÖØÊÓ£¬²¢½¥½¥³ÉΪÔÚ°²È«ÁìÓòµÄÒ»¸öÈÈÃÅ»°Ì⣬ÔÚ´Ëͬʱ£¬º§¿ÍÃÇÒ²ÇÄÇĵĽ«½¹µã×ªÒÆµ½ÍøÒ³Ó¦ÓóÌʽ¿ª·¢Ê±Ëù»á²úÉúµÄÈõµãÀ´½øÐй¥»÷ÓëÆÆ»µ¡£
ÃÀ¹úÁª°îóÒ×ίԱ»á(FTC)Ç¿ÁÒ½¨ÒéËùÓÐÆóÒµÐè×ñÑOWASPËù·¢²¼µÄÊ®´óWebÈõµã·À»¤ÊØÔò¡¢ÃÀ¹ú¹ú·À²¿ÒàÁÐΪ×î¼ÑʵÎñ£¬¹ú¼ÊÐÅÓÿ¨×ÊÁϰ²È« ¼¼ÊõPCI±ê×¼¸ü½«ÆäÁÐΪ±ØÒªÔª¼þ¡£Ä¿Ç°OWASPÓÐ30¶à¸ö½øÐÐÖеļƻ£¬°üÀ¨×îÖªÃûµÄOWASP Top 10(Ê®´óWebÈõµã)¡¢WebGoat(´ú×ï¸áÑò)Á·Ï°Æ½Ì¨¡¢°²È«PHP/Java/ASP.NetµÈ¼Æ»£¬Õë¶Ô²»Í¬µÄÈíÌ尲ȫÎÊÌâÔÚ½øÐÐÌÖÂÛÓëÑо¿¡£
µ±¹óµ¥Î»¾ö¶¨¿ª·ÅÍøÒ³·þÎñʱ£¬¾Í±ØÐëÈÃÀ´×ÔÓÚÈ«ÇòµÄÍøÒ³ÇëÇó½øÈ뵥λÄÚ²¿µÄÍøÒ³ËÅ·þÆ÷¡£º§¿Í¿ÉÒÔ½åÓÉÒþ²ØÔںϷ¨µÄÍøÒ³ÇëÇóÄÚ£¬Í¨¹ý·À»ðǽ¡¢ÈëÇÖÕì ²âϵͳ»òÆäËû·ÀÓùϵͳµÄÕì²â£¬Ìöø»ÊÖ®µÄ½øÈ뵥λÄÚ²¿»ò½åÓɵ¥Î»ÍøÕ¾³äµ±Ìø°åÓëÖмÌÕ¾¶øÏòÆäËûÊܺ¦Õß·¢¶¯¹¥»÷¡£ÕâÒâζ×ÅÆóÒµµÄÍøÒ³³ÌʽÂëÒ²±ØÐë³ÉΪ»ú¹Ø (¹¹)µ¥Î»Öܱߵݲȫ·À»¤Ö®Ò»£¬µ±µ¥Î»ÍøÒ³·þÎñµÄ¹æÄ£Ó븴ÔÓÐÔÔö¼Óʱ£¬µ¥Î»±©Â¶ÓÚÍâµÄ·çÏÕÒ²Öð½¥Ôö¼Ó¡£
Ö÷Ò³£ºhttps://www.owasp.org/index.php/Main_Page
À´×Ô:¿ªÔ´ÖйúÉçÇø