# Fortify 常見弱掃筆記 1.Mass Assignment: Insecure Binder Configuration、 ASP.NET MVC Bad Practices: Model With Optional and Required Properties **解法**:在Action加上[Bind("")]  2.Mass Assignment: Sensitive Field Exposure **解法**:在Model上方加上[BindProperties]  3.Cross-Site Scripting: DOM **解法**:加入htmlEncode function  4.Cookie Security: Overly Broad Domain、 Cookie Security: Overly Broad Path **解法**:options加上domain、path  5.Privacy Violation: Autocomplete **解法**:加上autocomplete="off"  6.Path Manipulation: Base Path Overwriting **解法**:加入Path.IsPathRooted判斷  7.Privacy Violation: Shoulder Surfing **解法**:密碼欄位加上[DataType(DataType.Password)] 
×
Sign in
Email
Password
Forgot password
or
By clicking below, you agree to our
terms of service
.
Sign in via Facebook
Sign in via Twitter
Sign in via GitHub
Sign in via Dropbox
Sign in with Wallet
Wallet (
)
Connect another wallet
New to HackMD?
Sign up