Protecting Applications · 保护应用程序
| English | 中文 | Pinyin · 拼音 |
|---|---|---|
| secure by design/sɪˈkjʊə baɪ dɪˈzaɪn/ | 安全设计 | ān quán shè jì |
| secure by default/sɪˈkjʊə baɪ dɪˈfɒlt/ | 默认安全 | mò rèn ān quán |
| input sanitization/ˈɪnpʊt ˌsænɪtaɪˈzeɪʃn/ | 输入清理 | shū rù qīng lǐ |
| control characters/kənˈtrəʊl ˈkærɪktəz/ | 控制字符 | kòng zhì zì fú |
Secure by design and default
- Secure by design 安全设计 builds security into every phase of development.
- Secure by default 默认安全 ships products with security features already on.
- Devices should be safe straight out of the box.
安全设计与默认安全
- 安全设计(secure by design)把安全构建到开发的每个阶段。
- 默认安全(secure by default)出厂时就已开启安全功能。
- 设备应开箱即安全。
Input sanitization
- Input sanitization 输入清理 removes or rejects dangerous control characters 控制字符.
- The single quote, double quote, and semicolon can manipulate a system.
- A good program checks input before processing it.
输入清理
- 输入清理(input sanitization)移除或拒绝危险的控制字符(control characters)。
- 单引号、双引号和分号能操纵系统。
- 好的程序在处理前先检查输入。
Does input sanitization block this attack? · 输入清理能否阻止此攻击?
Sanitization removes dangerous control characters, blocking SQL injection, XSS, and directory traversal. · 清理删除危险的控制字符,从而阻止SQL注入、XSS和目录遍历。
"Secure by default" means a product ships with... · “默认安全”意味着产品出厂时……
Secure by default = safe out of the box. · 默认安全 = 开箱即用即安全。
Which single defense blocks SQL injection, XSS, AND directory traversal? · 哪种单一防御能同时阻止SQL注入、XSS和目录遍历?
Input sanitization stops all three. · 输入清理 阻止所有三种攻击。
Dangerous characters like the single quote and semicolon are called ____ characters. · 单引号和分号等危险字符被称为 ____ 字符。
Control characters can manipulate a system. · 控制字符 可以操纵系统。
Input sanitization protects against which attacks? (Choose all) · 输入清理保护免受哪些攻击?(多选)
Jamming is a wireless attack, not an input attack. · 干扰是无线攻击,不是输入攻击。
One defense, many attacks
- Sanitization stops SQL injection attacks.
- It stops XSS attacks.
- It stops directory-traversal attacks too.
一种防御,多种攻击
- 清理阻止SQL注入攻击。
- 它阻止XSS攻击。
- 它也阻止目录遍历攻击。
"Secure by default" matters because most users never change default settings. If a product ships with security off, most installations stay insecure forever. The safe defaults must be on from the start.
"默认安全"很重要,因为大多数用户从不更改默认设置。如果产品出厂时安全功能关闭,大多数安装将永远保持不安全。安全的默认值必须从一开始就开启。
Secure by design builds security in from the earliest phase of development. · 安全设计从开发最早阶段就将安全内置其中。
Security is a design principle, not an add-on. · 安全是一项设计原则,而非附加组件。
A web form runs user input as part of a database query. If the app sanitizes the input — stripping quotes and semicolons — then ' OR '1'='1 is rendered harmless. The same sanitization also blocks XSS <script> tags and ../ traversal in one stroke.
一个网页表单把用户输入作为数据库查询的一部分运行。如果应用清理了输入——去掉引号和分号——那么 ' OR '1'='1 就变得无害。同样的清理也一并阻止XSS的 <script> 标签和 ../ 遍历。
Protect applications with secure by design (security in every phase) and secure by default (features on out of the box). Input sanitization — removing dangerous control characters — is the single defense that blocks SQL injection, XSS, and directory traversal at once.
用安全设计(每个阶段都有安全)和默认安全(开箱即开启功能)来保护应用。输入清理——移除危险的控制字符——是同时阻止SQL注入、XSS和目录遍历的单一防御。