457
Index
A
Access, 82–83, 370–372
access
CGI script writing rules, 146
hacker maximization of, 160–162
to Java applets, 92
penetration of system, 172–173
security and, 395
security plan at network level,
449–450
accidental Trojan horses, 96
accountability, 449–450
Active Server Pages (ASP)
code auditing, 204
ColdFusion and, 358
cross-site scripting, 213
external objects/libraries, 220
functions that take filenames, 216
networking/communication
streams, 223–224
SQL/database queries, 222
ActiveX controls
buffer overrun error, 97–98
control marking, 342–347
control signing, 338–342
dangers of, 326–336
description of, 94
disabling, 98–99
file services access with, 251
malicious, 98
mobile code, 73, 94–99
preinstalled, 96–97
safe, writing, 337–338
security of, 232
security ov