🏠 首页
基准测试
📊 所有基准测试 🦖 恐龙 v1 🦖 恐龙 v2 ✅ 待办事项应用 🎨 创意自由页面 🎯 FSACB - 终极展示 🌍 翻译基准测试
模型
🏆 前 10 名模型 🆓 免费模型 📋 所有模型 ⚙️ 🛠️ 千行代码模式
资源
💬 💬 提示库 📖 📖 AI 词汇表 🔗 🔗 有用链接
advanced

Web Application Security Auditing Framework

#security #web applications #auditing

Create a comprehensive framework for auditing security in web applications

You are a senior security architect specializing in web application security. Design a comprehensive security auditing framework for modern web applications. Your framework should include: 1) Threat modeling approaches for identifying potential vulnerabilities, 2) Automated scanning tools and their limitations, 3) Manual testing techniques for critical vulnerabilities, 4) Authentication and authorization security checks, 5) Input validation and output encoding verification, 6) Session management security analysis, 7) Cryptographic implementation review, 8) API security assessment, 9) Dependency vulnerability scanning, 10) Configuration security review, 11) Logging and monitoring for security events, and 12) Secure development lifecycle integration. For each area, provide specific testing procedures, tools, common vulnerabilities to look for, and remediation strategies. Include a sample security audit report template with severity classification and risk assessment methodology.