Here are the areas they went into:
Access Control
- Hidden items
- Item Protection
- Page Access Protection
Configuration
- Session Timeout
Cross-Site Scripting
- Column From LOV/Query (make use of )
- Direct Output
- Indirect Output
- Report Column Display Type
- Template Variables
Tip: make use of apex_escape.html, apex_escape.html_attribute, utl_url.escape
Data Protection
- Page Autocomplete
Warnings
- Direct URL
Thanks Nathan and Tim.
We use eSert from Enkitec and it is amazing what vulerabilities are uncovered from a security audit. All too often, security is an afterthought with developers... not any more for me!
ReplyDeleteI agree, anything is good; manual review of somebody else, automated review like tools like eSert and ApexSec help a lot in creating a secure environment...
ReplyDelete