[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
RE: [WEB SECURITY] Client-side validation in 2007?
- From: "Martin O'Neal" <martin.oneal@xxxxxxxxxxxx>
- Subject: RE: [WEB SECURITY] Client-side validation in 2007?
- Date: Sat, 13 Jan 2007 06:39:51 -0000
> how many people still find web applications using
> client-side validation being used for such things...
We still see many that have no validation and instead rely on the
database to enforce length and type (blurgh), but only a few that have
client-side only validation.
I would say the percentage of applications that we review that validate
thoroughly at all entry points (and respond appropriately) is less than
5%.
Martin...
----------------------------------------------------------------------------
The Web Security Mailing List:
http://www.webappsec.org/lists/websecurity/
The Web Security Mailing List Archives:
http://www.webappsec.org/lists/websecurity/archive/
http://www.webappsec.org/rss/websecurity.rss [RSS Feed]
Brought to you by http://www.webappsec.org
Search this site
|