AppScan 8.0.3 Security Vulnerability Scan Summary

Source: Internet
Author: User

This document documents the security vulnerabilities and solutions for scanning through the AppScan 8.0.3 tool,

1. Authentication bypass using SQL injection

Problem Description:

Solution:

It is generally filtered by xssfilter filter, and some key characters are filtered through xssfiiter. You can refer to the blog

2. Decrypted Login Request

Typically handled by configuring SSL for WebLogic

Problem Description:

Solution:

Configure the server so that it can be accessed with SSL, you can refer to the blog post

3. Cross-site access

Problem Description:

Solution:

Generally filter by Csrffilter filter, you can refer to the blog post

4. Insufficient account closure

Problem Description:

Solution:  

You cannot log on by configuring user lock

5. Login error Message Credential enumeration

Problem Description:

Solution:

Each logon failure error message is the same, for example, the user name or password error, through such a prompt to deal with the problem.

AppScan 8.0.3 Security Vulnerability Scan Summary

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.