LEARN how to secure your code- BROKEN ACCESS CONTROL
- INPUT VALIDATION
- Command Injection
- Cross Site Scripting (XSS)
- CRYPTOGRAPHIC FAILURES
- INJECTION
- Log4Shell
- SECURITY MISCONFIGURATION
- Cross Site Request Forgery
- SESSION WEAKNESS
- COOKIE WEAKNESS
- Server-Side Request Forgery (SSRF)
- Untrusted Deserialization
- XML External Entity (XXE)
- Use Contrast
- Learn DevSec
Learn DevSec
The Contrast Learn Guide is for developers like you.
We strive to use our years of experience in the field to provide the most helpful point of reference.
While we will walk you through the correct techniques to fix and prevent attacks, we aim to empower Engineers within your team and organization to make the most informed decision regarding your security landscape.
Contribute
Do you have another attack example to share?
Are there any descriptions that are unclear?
We welcome you to contribute to our guide by submitting an issue or pull request.
Developer Resources
Contrast CodeSec
CodeSec is Contrast Security’s new free developer security tool that brings the fastest and most accurate scanner in the market right to developers for FREE.
Providing actionable remediation guidance, CodeSec by Contrast enables developers to get up and running in less than five minutes.
Here’s how:
1. START NOW
Head over to https://www.contrastsecurity.com/developer to begin.
2. INSTALL VIA CLI
CodeSec also offers multiple install options including NPM, Artifactory, and Homebrew
Via Homebrew