Difference between revisions of "OWASP .NET Recommended Resources"

From OWASP
Jump to: navigation, search
m (.NET Recommended moved to OWASP .NET Recommended Resources: New title for clarity)
 
(30 intermediate revisions by 5 users not shown)
Line 1: Line 1:
OWASP .NET Recommended Resources
+
{| align="right" class="wikitable"
 +
|-
 +
! OWASP .NET Quick Reference
 +
|-
 +
|
 +
*[[OWASP Code Review Project]]<br />
 +
*[[OWASP Testing Guide]]<br />
 +
|-
 +
|}
 +
==OWASP .NET Recommended Resources==
 +
 
 +
This is a canonical list of outside resources for .NET developers seeking security information.
 +
 
 +
===Blogs & People===
 +
 
 +
[http://securitybuddha.com/ Mark Curphrey's Blog]
 +
 
 +
[http://blogs.msdn.com/michael_howard/default.aspx Michael Howard's Blog]
 +
 
 +
[http://blogs.msdn.com/jmeier/archive/tags/Security/default.aspx J.D. Meier's Blog]
 +
 
 +
[http://www.leastprivilege.com Dominick Baier's Blog]
 +
 
 +
[http://blogs.msdn.com/shawnfa/default.aspx Shawn Farkas' Blog]
 +
 
 +
[http://blogs.msdn.com/ace_team/ Microsoft's ACE Team]
 +
 
 +
[http://www.troyhunt.com/ Troy Hunt's Blog]
 +
 
 +
===Advisories, Articles & Projects===
 +
 
 +
[http://msdn.microsoft.com/en-us/library/ee658105.aspx Security and Operational Guidance for .NET Applications]
 +
 
 +
[http://msdn2.microsoft.com/en-us/library/yedba920.aspx ASP.NET Security Architecture]
 +
 
 +
[http://msdn.microsoft.com/en-us/library/ms998404.aspx patterns & practices Security Engineering Index]
 +
 
 +
[http://msdn.microsoft.com/en-us/library/ms998408.aspx patterns & practices Security Guidance for Applications Index]
 +
 
 +
[http://msdn.microsoft.com/en-us/library/ms954725.aspx patterns & practices Security Guidance for .NET Framework 2.0]
 +
 
 +
[http://msdn.microsoft.com/en-us/library/Ee817643(pandp.10).aspx Authentication in ASP.NET: .NET Security Guidance]
 +
 
 +
[http://msdn2.microsoft.com/en-us/library/ms998404.aspx Security Engineering]
 +
 
 +
[http://www.developer.com/design/article.php/3607471 Solutions to SOA Security]
 +
 
 +
[http://en.wikipedia.org/wiki/WS-%2A Web Service Specifications]
 +
 
 +
[http://wcfsecurityguide.codeplex.com/ Security Guidance for Windows Communication Foundation]
 +
 
 +
[http://www.microsoft.com/technet/security/advisory/954462.mspx Microsoft Security Advisory (954462) (SQL Injection Advisory)]
 +
 
 +
===Online References, Training===
 +
 
 +
[http://msdn2.microsoft.com/en-us/practices/default.aspx Patterns and Practices]
 +
 
 +
[http://msdn.microsoft.com/en-us/security/default.aspx MSDN Security Developer Center]
 +
 
 +
[http://blogs.technet.com/feliciano_intini/pages/microsoft-blogs-and-web-resources-about-security.aspx Microsoft Security Resources]
 +
 
 +
[http://pluralsight.com/training/Courses#security Pluralsight Security Course Catalog]
 +
 
 +
[http://www.troyhunt.com/2010/05/owasp-top-10-for-net-developers-part-1.html OWASP Top 10 for .NET developers - Troy Hunt]
 +
 
 +
[http://www.teammentor.net/teamMentor TeamMentor]
 +
 
 +
===Books and Publications===
 +
 
 +
[http://www.microsoft.com/mspress/books/5957.aspx Writing Secure Code], Michael Howard and David LeBlanc
 +
 
 +
[http://www.microsoft.com/downloads/details.aspx?familyid=2412c443-27f6-4aac-9883-f55ba5b01814&displaylang=en&Hash=4fZb2FzZ7%2bmaj0VqoUbFZzzw0WW5%2bxWjK3XBVit5eX%2b%2bB90vmLtZlAstlNg9cRu6Pg%2b50DNCMhGT6ADei7DgFg%3d%3d Microsoft Security Development Lifecycle 3.2]
 +
 
 +
[http://msdn.microsoft.com/en-us/library/aa302415.aspx Building Secure ASP.NET Applications: Authentication, Authorization, and Secure Communication], J.D. Meier, Alex Mackman, Michael Dunner, and Srinath Vasireddy
 +
 
 +
[http://msdn.microsoft.com/en-us/library/ms994921.aspx Improving Web Application Security: Threats and Countermeasures], J.D. Meier, Alex Mackman, Michael Dunner, Srinath Vasireddy, Ray Escamilla and Anandha Murukan
 +
 
 +
[http://msdn.microsoft.com/en-gb/security/aa473878.aspx Developer Highway Code], Microsoft Corp, United Kingdom
 +
 
 +
[http://securitydriven.net/ Security Driven .NET], Stan Drapkin
 +
 
 +
===Tools===
 +
 
 +
[http://blogs.msdn.com/b/sdl/archive/2014/04/15/introducing-microsoft-threat-modeling-tool-2014.aspx Microsoft Threat Modeling Tool 2014]
 +
 
 +
[http://msdn.microsoft.com/en-us/security/aa973814.aspx Anti-Cross Site Scripting]
 +
 
 +
[http://learn.iis.net/page.aspx/473/using-urlscan URLScan]
 +
 
 +
[http://support.microsoft.com/kb/954476 Microsoft Source Code Analyzer]
 +
 
 +
[http://support.microsoft.com/kb/954476 MS Source Code Analyser for SQL Injection]

Latest revision as of 10:00, 8 May 2014

OWASP .NET Quick Reference

OWASP .NET Recommended Resources

This is a canonical list of outside resources for .NET developers seeking security information.

Blogs & People

Mark Curphrey's Blog

Michael Howard's Blog

J.D. Meier's Blog

Dominick Baier's Blog

Shawn Farkas' Blog

Microsoft's ACE Team

Troy Hunt's Blog

Advisories, Articles & Projects

Security and Operational Guidance for .NET Applications

ASP.NET Security Architecture

patterns & practices Security Engineering Index

patterns & practices Security Guidance for Applications Index

patterns & practices Security Guidance for .NET Framework 2.0

Authentication in ASP.NET: .NET Security Guidance

Security Engineering

Solutions to SOA Security

Web Service Specifications

Security Guidance for Windows Communication Foundation

Microsoft Security Advisory (954462) (SQL Injection Advisory)

Online References, Training

Patterns and Practices

MSDN Security Developer Center

Microsoft Security Resources

Pluralsight Security Course Catalog

OWASP Top 10 for .NET developers - Troy Hunt

TeamMentor

Books and Publications

Writing Secure Code, Michael Howard and David LeBlanc

Microsoft Security Development Lifecycle 3.2

Building Secure ASP.NET Applications: Authentication, Authorization, and Secure Communication, J.D. Meier, Alex Mackman, Michael Dunner, and Srinath Vasireddy

Improving Web Application Security: Threats and Countermeasures, J.D. Meier, Alex Mackman, Michael Dunner, Srinath Vasireddy, Ray Escamilla and Anandha Murukan

Developer Highway Code, Microsoft Corp, United Kingdom

Security Driven .NET, Stan Drapkin

Tools

Microsoft Threat Modeling Tool 2014

Anti-Cross Site Scripting

URLScan

Microsoft Source Code Analyzer

MS Source Code Analyser for SQL Injection