Do Not Use the Back Door!
netspi.com | blog | #code-review | #authentication | #backdoor | #application-security | #secure-development
Summary
In system development a "backdoor" creates a way of bypassing normal authentication to allow access to a system.
- Published
- Collected
Related coverage
blog ·
netspi.com
Outsourcing application development – what is missing?
Outsourcing guides rarely address security: require secure coding training, put security reviews in contracts, and demand a penetration test plus code review with mitigation before release.
blog ·
netspi.com
Code Review – is automated testing enough?
Automated scanners like Fortify and Checkmarx satisfy PCI DSS 6.3.2 but miss flaws found in manual review, especially authentication bugs, and false positives often overwhelm developers.
blog ·
netspi.com
Happy New Year – Have you made your application testing resolution yet?
A New Year reminder that code review and penetration testing each miss vulnerabilities the other finds, so organizations should do both and remediate findings instead of delaying fixes.
blog ·
netspi.com
Manual vs. Automated Testing
I’ve always been a firm believer in incorporating manual testing as part of any security assessment; after all, a human is the best judge of evaluating the contents of application output, and best able to truly understand how an application is supposed to function.
blog ·
netspi.com
Are We Ready for a Security Software Assurance Program?
Integrating security checks and balances with your application development processes is certainly uncharted territory for many security professionals.
blog ·
bugbunny.ai
Secure Software Development Lifecycle: Building Security Into the Work
Building security into normal delivery: the SSDLC guide argues security decisions must land at design review, feature kickoff, PR and release time—not as a late gate once architecture is locked.
Skip to content