Quantcast
Channel: SCN: Message List - Security
Viewing all articles
Browse latest Browse all 5338

Re: Authorization Bypass Prevention

$
0
0

Force users to use standard transactional logic i.e. only run their authorised.  No direct access to programs, function modules & all that good stuff.  Ensure no-one has ability to debug & replace or they can hobble most auth checks.

 

That should give you somewhere to start

 

cheers


Viewing all articles
Browse latest Browse all 5338

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>