Penetration Testing mailing list archives

To validate or not to validate: Client side validation


From: pand0ra <pand0ra.usa () gmail com>
Date: Mon, 19 Apr 2010 14:41:47 -0600

Question: You are doing code review and come across a javascript
application that does not do input validation. Would you have the
developer go back and write in input validation? If so, why? If not,
why?

------------------------------------------------------------------------
This list is sponsored by: Information Assurance Certification Review Board

Prove to peers and potential employers without a doubt that you can actually do a proper penetration test. IACRB CPT 
and CEPT certs require a full practical examination in order to become certified. 

http://www.iacertification.org
------------------------------------------------------------------------


Current thread: