- OWASP: SQL Injection
- OWASP: Guide to SQL Injection
- OWASP: SQL Injection Prevention Cheat Sheet
- OWASP: Reviewing Code for SQL Injection
- OWASP: Testing for SQL Injection
- OWASP: Cross-site Scripting (XSS)
- OWASP: XSS (Cross Site Scripting) Prevention Cheat Sheet
- OWASP: Reviewing Code for Cross-site scripting
- OWASP: Testing for Cross site scripting
- WASC: Remote File Inclusion
- CWE: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP File Inclusion')
- Wikipedia: Remote File Inclusion
Soluções
- Suhosin PHP module (por que usar e lista de funcionalidades)
- sqlmap: automatic SQL injection tool (muito cuidado se for usar esta ferramenta)
- fimap: a little tool for local and remote file inclusion auditing and exploitation (muito cuidado se for usar esta ferramenta)
Juntos podemos fazer mais e melhor.
[]’s







Entrar
Cadastre-se








