Verb Tampering Prevention
Insecure Configuration
<Directory "/var/www/html/admin"> AuthType Basic AuthName "Admin Panel" AuthUserFile /etc/apache2/.htpasswd <Limit GET> Require valid-user </Limit> </Directory><security-constraint> <web-resource-collection> <url-pattern>/admin/*</url-pattern> <http-method>GET</http-method> </web-resource-collection> <auth-constraint> <role-name>admin</role-name> </auth-constraint> </security-constraint><system.web> <authorization> <allow verbs="GET" roles="admin"> <deny verbs="GET" users="*"> </deny> </allow> </authorization> </system.web>
Insecure Coding
Conclusion:
Last updated