Web Application Security

Developing and operating secure web applications is an ongoing process.

What does Web Application Security mean?

Web application security is the specialization of aramido IT Security Consulting. The process of making a web application secure involves several steps. Starting with the design of the architecture according to the principles of Security by Design through the implementation of the code in various programming languages such as Java, PHP, or .Net and frameworks like Symfony, Ruby on Rails, or AngularJS, various best practices must be observed.

The most renowned organization dedicated to web application security is the Open Worldwide Application Security Project (OWASP). The best-known OWASP project is the OWASP Top Ten, the list of the ten most common web application vulnerabilities, which is updated every three years. These include, for example, SQL injections, cross-site scripting (XSS), and broken authorization. OWASP also offers web developers a wealth of other helpful resources and tools to support the development of secure web applications, such as the OWASP Proactive Controls, a collection of guidelines for secure programming, or the OWASP Cheat Sheets with checklists and best practices for various development environments and programming languages (e.g., HTML5, REST, XML, AJAX, iOS).

Do you have web applications in use that were developed wholly or partially individually? Then it is advisable to have these web applications regularly examined through web application penetration tests as part of the security process. On the overview page for aramido's penetration testing offering, you can request a free sample report for a web application penetration test .


All blog articles on the subject of Web Application Security
Hannah Schneider

Published on 21.10.2021 in the category Web Application Security published.

The New OWASP Top 10 - 2021

The OWASP Top 10 - 2021 describes the ten most common security risks for web applications. They help developers implement applications securely. (read more)

Andreas Sperber

Published on 21.11.2018 in the category Web Application Security published.

What are the OWASP Top 10 - 2017?

The OWASP Top 10 - 2017 describes the ten most common security risks for web applications. They help developers implement applications securely. (read more)

Daniel Matesic

Published on 13.06.2018 in the category Web Application Security published.

52nd OWASP Meetup - Guided Hacking of a Web Application

At the 52nd OWASP Meetup, numerous security risks, including the OWASP Top 10, were illustrated through guided hacking of a web application. (read more)

Andreas Sperber

Published on 15.12.2016 in the category Web Application Security published.

Live-Hacking a Symfony application

Andreas Sperber from aramido is a guest at SensioLabs in Cologne on Dec 21, 2016. He hacks a Symfony app and shows what can be done for IT security. (read more)

Armin Harbrecht

Published on 19.10.2016 in the category Web Application Security published.

HTTPS on the Rise - Why everyone must switch their site to HTTPS in 2017

Encrypted communication via HTTPS was long only for highly secure web applications. Soon, however, Google will penalize unencrypted websites. (read more)

Armin Harbrecht

Published on 15.04.2016 in the category Web Application Security published.

Piwik Security – Securely Analyzing Web Applications

The aramido best practice for Piwik shows what to look out for when using the web analytics tool. The Piwik security checklist helps you secure your Piwik installation. (read more)