{
    "archive_path": "archive/1736015745.600104",
    "base_url": "github.com/FallibleInc/security-guide-for-developers",
    "basename": "security-guide-for-developers",
    "bookmarked_date": "2025-01-04 18:35",
    "canonical": {
        "archive_org_path": "https://web.archive.org/web/github.com/FallibleInc/security-guide-for-developers",
        "dom_path": "output.html",
        "favicon_path": "favicon.ico",
        "git_path": "git/",
        "google_favicon_path": "https://www.google.com/s2/favicons?domain=github.com",
        "headers_path": "headers.json",
        "htmltotext_path": "htmltotext.txt",
        "index_path": "index.html",
        "media_path": "media/",
        "mercury_path": "mercury/content.html",
        "pdf_path": "output.pdf",
        "readability_path": "readability/content.html",
        "screenshot_path": "screenshot.png",
        "singlefile_path": "singlefile.html",
        "warc_path": "warc/",
        "wget_path": null
    },
    "domain": "github.com",
    "downloaded_at": "2025-01-04T18:39:10.992109+00:00",
    "downloaded_datestr": "2025-01-04 18:39",
    "extension": "",
    "hash": "19SJW2XKGR21FRRPVF27",
    "history": {
        "archive_org": [
            {
                "cmd": [
                    "/usr/bin/curl",
                    "--silent",
                    "--location",
                    "--compressed",
                    "--proxy",
                    "socks5://tor-socks-proxy:9150",
                    "--head",
                    "--max-time",
                    "60",
                    "--user-agent",
                    "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36 ArchiveBox/{VERSION} (+https://github.com/ArchiveBox/ArchiveBox/)",
                    "https://web.archive.org/save/https://github.com/FallibleInc/security-guide-for-developers"
                ],
                "cmd_version": "8.10.1",
                "end_ts": "2025-01-04T18:39:54.023789+00:00",
                "index_texts": null,
                "output": "ArchiveError: Failed to find \"content-location\" URL header in Archive.org response.",
                "pwd": "/data/archive/1736015745.600104",
                "schema": "ArchiveResult",
                "start_ts": "2025-01-04T18:39:52.529207+00:00",
                "status": "failed"
            }
        ],
        "dom": [
            {
                "cmd": [
                    "/usr/bin/chromium-browser",
                    "--proxy-server=socks5://tor-socks-proxy:9150",
                    "--disable-features=DarkMode",
                    "--run-all-compositor-stages-before-draw",
                    "--hide-scrollbars",
                    "--autoplay-policy=no-user-gesture-required",
                    "--no-first-run",
                    "--use-fake-ui-for-media-stream",
                    "--use-fake-device-for-media-stream",
                    "--simulate-outdated-no-au='Tue, 31 Dec 2099 23:59:59 GMT'",
                    "--headless=new",
                    "--no-sandbox",
                    "--no-zygote",
                    "--disable-dev-shm-usage",
                    "--disable-software-rasterizer",
                    "--disable-sync",
                    "--window-size=1440,2000",
                    "--user-agent=Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36 ArchiveBox/{VERSION} (+https://github.com/ArchiveBox/ArchiveBox/)",
                    "--user-data-dir=/data/personas/Default/chrome_profile",
                    "--profile-directory=Default",
                    "--dump-dom",
                    "https://github.com/FallibleInc/security-guide-for-developers"
                ],
                "cmd_version": "131.0.6778",
                "end_ts": "2025-01-04T18:39:27.379674+00:00",
                "index_texts": null,
                "output": "output.html",
                "pwd": "/data/archive/1736015745.600104",
                "schema": "ArchiveResult",
                "start_ts": "2025-01-04T18:39:15.757586+00:00",
                "status": "succeeded"
            }
        ],
        "favicon": [
            {
                "cmd": [
                    "/usr/bin/curl",
                    "--silent",
                    "--location",
                    "--compressed",
                    "--proxy",
                    "socks5://tor-socks-proxy:9150",
                    "--max-time",
                    "60",
                    "--output",
                    "favicon.ico",
                    "--user-agent",
                    "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36 ArchiveBox/{VERSION} (+https://github.com/ArchiveBox/ArchiveBox/)",
                    "https://www.google.com/s2/favicons?domain=github.com"
                ],
                "cmd_version": "8.10.1",
                "end_ts": "2025-01-04T18:39:14.576801+00:00",
                "index_texts": null,
                "output": "favicon.ico",
                "pwd": "/data/archive/1736015745.600104",
                "schema": "ArchiveResult",
                "start_ts": "2025-01-04T18:39:11.067831+00:00",
                "status": "succeeded"
            }
        ],
        "git": [],
        "headers": [
            {
                "cmd": [
                    "/usr/bin/curl",
                    "--silent",
                    "--location",
                    "--compressed",
                    "--proxy",
                    "socks5://tor-socks-proxy:9150",
                    "--head",
                    "--max-time",
                    "60",
                    "--user-agent",
                    "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36 ArchiveBox/{VERSION} (+https://github.com/ArchiveBox/ArchiveBox/)",
                    "https://github.com/FallibleInc/security-guide-for-developers"
                ],
                "cmd_version": "8.10.1",
                "end_ts": "2025-01-04T18:39:15.689054+00:00",
                "index_texts": null,
                "output": "headers.json",
                "pwd": "/data/archive/1736015745.600104",
                "schema": "ArchiveResult",
                "start_ts": "2025-01-04T18:39:14.725798+00:00",
                "status": "succeeded"
            }
        ],
        "htmltotext": [
            {
                "cmd": [
                    "(internal) archivebox.extractors.htmltotext",
                    "./{singlefile,dom}.html"
                ],
                "cmd_version": "0.8.5rc51",
                "end_ts": "2025-01-04T18:39:46.028542+00:00",
                "index_texts": [
                    "(https://github.githubassets.com) (https://avatars.githubusercontent.com) (https://github-cloud.s3.amazonaws.com) (https://user-images.githubusercontent.com/) (https://github.githubassets.com) (https://avatars.githubusercontent.com) (https://github.githubassets.com/assets/light-0cfd1fd8509e.css) (https://github.githubassets.com/assets/dark-d782f59290e2.css) (https://github.githubassets.com/assets/primer-primitives-953961b66e63.css) (https://github.githubassets.com/assets/primer-4430d3c2c150.css) (https://github.githubassets.com/assets/global-47b8b2ca21ae.css) (https://github.githubassets.com/assets/github-e72829f5538b.css) (https://github.githubassets.com/assets/repository-d031bcc14e1b.css) (https://github.githubassets.com/assets/code-9e1913b328be.css) (https://github.githubassets.com/assets/primer-react.797c8ec006b327590422.module.css) (https://github.githubassets.com/assets/notifications-subscriptions-menu.1bcff9205c241e99cff2.module.css) (https://github.githubassets.com/assets/primer-react.797c8ec006b327590422.module.css) (https://github.githubassets.com/assets/notifications-subscriptions-menu.1bcff9205c241e99cff2.module.css) GitHub - FallibleInc/security-guide-for-developers: Security Guide for Developers (\u5b9e\u7528\u6027\u5f00\u53d1\u4eba\u5458\u5b89\u5168\u987b\u77e5) (repo_source) (https://github.githubassets.com/) (/opensearch.xml) (GitHub) (https://github.com/fluidicon.png) (GitHub) (https://github.com/FallibleInc/security-guide-for-developers) (https://github.githubassets.com/assets/pinned-octocat-093da3e6fa40.svg) (https://github.githubassets.com/favicons/favicon.png) (https://github.githubassets.com/favicons/favicon.svg) (/manifest.json)  Skip to content   (https://github.githubassets.com/assets/primer-react.797c8ec006b327590422.module.css)    Navigation Menu Toggle navigation         (/)    (/login?return_to=https%3A%2F%2Fgithub.com%2FFallibleInc%2Fsecurity-guide-for-developers) Sign in    Product    (https://github.com/features/copilot)    GitHub Copilot Write better code with AI    (https://github.com/features/security)    Security Find and fix vulnerabilities    (https://github.com/features/actions)   Actions Automate any workflow    (https://github.com/features/codespaces)    Codespaces Instant dev environments    (https://github.com/features/issues)   Issues Plan and track work    (https://github.com/features/code-review)    Code Review Manage code changes    (https://github.com/features/discussions)    Discussions Collaborate outside of code    (https://github.com/features/code-search)    Code Search Find more, search less       Explore (https://github.com/features) All features   (https://docs.github.com) Documentation     (https://skills.github.com) GitHub Skills     (https://github.blog) Blog          Solutions    By company size (https://github.com/enterprise) Enterprises   (https://github.com/team) Small and medium teams   (https://github.com/enterprise/startups) Startups     By use case (/solutions/use-case/devsecops) DevSecOps   (/solutions/use-case/devops) DevOps   (/solutions/use-case/ci-cd) CI/CD   (/solutions/use-case) View all use cases      By industry (/solutions/industry/healthcare) Healthcare   (/solutions/industry/financial-services) Financial services   (/solutions/industry/manufacturing) Manufacturing   (/solutions/industry/government) Government   (/solutions/industry) View all industries      (/solutions) View all solutions       Resources    Topics (/resources/articles/ai) AI   (/resources/articles/devops) DevOps   (/resources/articles/security) Security   (/resources/articles/software-development) Software Development   (/resources/articles) View all      Explore (https://resources.github.com/learn/pathways) Learning Pathways     (https://resources.github.com) White papers, Ebooks, Webinars     (https://github.com/customer-stories) Customer Stories   (https://partner.github.com) Partners     (https://github.com/solutions/executive-insights) Executive Insights        Open Source    (/sponsors) GitHub Sponsors Fund open source developers      (https://github.com/readme) The ReadME Project GitHub community articles      Repositories (https://github.com/topics) Topics   (https://github.com/trending) Trending   (https://github.com/collections) Collections        Enterprise    (/enterprise)     Enterprise platform AI-powered developer platform      Available add-ons (https://github.com/enterprise/advanced-security)    Advanced Security Enterprise-grade security features    (/features/copilot#enterprise)    GitHub Copilot Enterprise-grade AI features    (/premium-support)    Premium Support Enterprise-grade 24/7 support         (https://github.com/pricing) Pricing    (Search or jump to...)    Search or jump to...      Search code, repositories, users, issues, pull requests... Search        ()   Clear                (https://docs.github.com/search-github/github-code-search/understanding-github-code-search-syntax) Search syntax tips          Provide feedback         (718eBPm5/j7xYUig8gPBJr8j9OW1sZC4zzAKuyISh7VXtdfUdNtuAYFGa918PJNoII3CedpYDALglC1nNKVkGw==) We read every piece of feedback, and take your input very seriously.  Include my email address so I can be contacted    Cancel  Submit feedback     Saved searches  Use saved searches to filter your results more quickly         (ejYL86/Jb/LVyuA4QMx3aqlvp0uxBM+wMUMlrQrACMuWLFHEppS1JRi0kyGmpPpkU/8fFIMLIpyuk4t/0FTJbw==)  Name (github-ruby) (X3jxl5hUPHMkQjwZZIZYEG0kq8uwWoh7rKHjnPqGNShRF+01UQU+sHKX9aZs6Vc50dS1v+qgZaEHj2ES553ipQ==)   Query ((repo:mona/a OR repo:mona/b) AND lang:python)  To see all available qualifiers, see our (https://docs.github.com/search-github/github-code-search/understanding-github-code-search-syntax) documentation .        Cancel  Create saved search        (/login?return_to=https%3A%2F%2Fgithub.com%2FFallibleInc%2Fsecurity-guide-for-developers) Sign in   (/signup?ref_cta=Sign+up&ref_loc=header+logged+out&ref_page=%2F%3Cuser-name%3E%2F%3Crepo-name%3E&source=header-repo&source_repo=FallibleInc%2Fsecurity-guide-for-developers) Sign up  Reseting focus        You signed in with another tab or window. () Reload to refresh your session. You signed out in another tab or window. () Reload to refresh your session. You switched accounts on another tab or window. () Reload to refresh your session.    Dismiss alert       (/FallibleInc) FallibleInc   / (/FallibleInc/security-guide-for-developers) security-guide-for-developers   Public   (/login?return_to=%2FFallibleInc%2Fsecurity-guide-for-developers)   Notifications  You must be signed in to change notification settings  (/login?return_to=%2FFallibleInc%2Fsecurity-guide-for-developers)   Fork (1,602) 1.6k   (/login?return_to=%2FFallibleInc%2Fsecurity-guide-for-developers)   Star  (20,949) 20.9k       Security Guide for Developers (\u5b9e\u7528\u6027\u5f00\u53d1\u4eba\u5458\u5b89\u5168\u987b\u77e5)    (https://git.io/security) (https://git.io/security) git.io/security   (/FallibleInc/security-guide-for-developers/stargazers)   20.9k stars  (/FallibleInc/security-guide-for-developers/forks)   1.6k forks  (/FallibleInc/security-guide-for-developers/branches)   Branches  (/FallibleInc/security-guide-for-developers/tags)   Tags  (/FallibleInc/security-guide-for-developers/activity)   Activity   (/login?return_to=%2FFallibleInc%2Fsecurity-guide-for-developers)   Star     (/login?return_to=%2FFallibleInc%2Fsecurity-guide-for-developers)   Notifications  You must be signed in to change notification settings      (/FallibleInc/security-guide-for-developers)   Code (Not available)    (/FallibleInc/security-guide-for-developers/pulls)   Pull requests (12) 12   (/FallibleInc/security-guide-for-developers/actions)   Actions (Not available)    (/FallibleInc/security-guide-for-developers/projects)   Projects (0) 0   (/FallibleInc/security-guide-for-developers/security)   Security   (/FallibleInc/security-guide-for-developers/pulse)   Insights (Not available)        Additional navigation options (/FallibleInc/security-guide-for-developers)    Code    (/FallibleInc/security-guide-for-developers/pulls)    Pull requests    (/FallibleInc/security-guide-for-developers/actions)    Actions    (/FallibleInc/security-guide-for-developers/projects)    Projects    (/FallibleInc/security-guide-for-developers/security)    Security    (/FallibleInc/security-guide-for-developers/pulse)    Insights               FallibleInc/security-guide-for-developers (https://github.githubassets.com/assets/primer-react.797c8ec006b327590422.module.css) (https://github.githubassets.com/assets/repos-overview.9cc263aa0716ce801059.module.css)      master           (/FallibleInc/security-guide-for-developers/branches)    2  Branches    (/FallibleInc/security-guide-for-developers/tags)    0  Tags     (/FallibleInc/security-guide-for-developers/branches)    (/FallibleInc/security-guide-for-developers/tags)         (Go to file) ()     Go to file          Code              Folders and files Name  Name  (Last commit message) Last commit message   (Last commit date) Last commit date     Latest commit (/abhishek-anand) (abhishek-anand)  (/FallibleInc/security-guide-for-developers/commits?author=abhishek-anand) abhishek-anand    (/FallibleInc/security-guide-for-developers/commit/6f4f0bbae46b53772584f83f519c1f087e5a4029) Merge pull request (https://github.com/FallibleInc/security-guide-for-developers/pull/46) #46 (/FallibleInc/security-guide-for-developers/commit/6f4f0bbae46b53772584f83f519c1f087e5a4029) from dmcgill50/patch-1       (Feb 20, 2017, 8:26 AM UTC) Feb 20, 2017   (/FallibleInc/security-guide-for-developers/commit/6f4f0bbae46b53772584f83f519c1f087e5a4029) 6f4f0bb \u00b7 (Feb 20, 2017, 8:26 AM UTC) Feb 20, 2017   History (/FallibleInc/security-guide-for-developers/commits/master/)    146 Commits        (/FallibleInc/security-guide-for-developers/commits/master/)               (images) (/FallibleInc/security-guide-for-developers/tree/master/images) images        (images) (/FallibleInc/security-guide-for-developers/tree/master/images) images      (New Chapter Added - HTTPS Explained) (/FallibleInc/security-guide-for-developers/commit/c6f4be9be69e1a84deee54985a9183630e389b6b) New Chapter Added - HTTPS Explained    (Dec 21, 2016, 7:31 AM UTC) Dec 21, 2016      (img) (/FallibleInc/security-guide-for-developers/tree/master/img) img        (img) (/FallibleInc/security-guide-for-developers/tree/master/img) img      (new padlock img) (/FallibleInc/security-guide-for-developers/commit/1d70b90cc8ac1bb87634dbe22bb227a3b5142971) new padlock img    (Aug 17, 2016, 9:44 AM UTC) Aug 17, 2016      (README-zh.md) (/FallibleInc/security-guide-for-developers/blob/master/README-zh.md) README-zh.md        (README-zh.md) (/FallibleInc/security-guide-for-developers/blob/master/README-zh.md) README-zh.md      (correct wrong words and polish some sentences in Chninese version) (/FallibleInc/security-guide-for-developers/commit/d1857b9b4ac2193dd59c00afa40d176de4e842da) correct wrong words and polish some sentences in Chninese version    (Aug 9, 2016, 2:32 AM UTC) Aug 9, 2016      (README.md) (/FallibleInc/security-guide-for-developers/blob/master/README.md) README.md        (README.md) (/FallibleInc/security-guide-for-developers/blob/master/README.md) README.md      (Update README.md\n\nSmall grammar correction) (/FallibleInc/security-guide-for-developers/commit/cb7f5d8b1fc678d0adad2a222a3b3d83e76eb6a0) Update README.md    (Jan 4, 2017, 1:25 PM UTC) Jan 4, 2017      (https.md) (/FallibleInc/security-guide-for-developers/blob/master/https.md) https.md        (https.md) (/FallibleInc/security-guide-for-developers/blob/master/https.md) https.md      (merged) (/FallibleInc/security-guide-for-developers/commit/8de7a5a6e2adaf8c09446bee7986155eab62c658) merged    (Dec 21, 2016, 7:41 AM UTC) Dec 21, 2016      (security-checklist-zh.md) (/FallibleInc/security-guide-for-developers/blob/master/security-checklist-zh.md) security-checklist-zh.md        (security-checklist-zh.md) (/FallibleInc/security-guide-for-developers/blob/master/security-checklist-zh.md) security-checklist-zh.md      (correct wrong words and polish some sentences) (/FallibleInc/security-guide-for-developers/commit/54046c383988e8a99e216a411dc853fdcd47b1ef) correct wrong words and polish some sentences    (Aug 8, 2016, 12:59 PM UTC) Aug 8, 2016      (security-checklist.md) (/FallibleInc/security-guide-for-developers/blob/master/security-checklist.md) security-checklist.md        (security-checklist.md) (/FallibleInc/security-guide-for-developers/blob/master/security-checklist.md) security-checklist.md      (Update HSTS preload list submission url) (/FallibleInc/security-guide-for-developers/commit/eb1c925dc847215a61dc09847f1b1c61960afc4b) Update HSTS preload list submission url    (Feb 20, 2017, 8:11 AM UTC) Feb 20, 2017      (vulnerabilities-stats-zh.md) (/FallibleInc/security-guide-for-developers/blob/master/vulnerabilities-stats-zh.md) vulnerabilities-stats-zh.md        (vulnerabilities-stats-zh.md) (/FallibleInc/security-guide-for-developers/blob/master/vulnerabilities-stats-zh.md) vulnerabilities-stats-zh.md      (correct wrong words and polish some sentences in Chninese version) (/FallibleInc/security-guide-for-developers/commit/f9b42e4a95f0e2ce2160da9e93b2fba8f5dc17d0) correct wrong words and polish some sentences in Chninese version    (Aug 9, 2016, 2:30 AM UTC) Aug 9, 2016      (vulnerabilities-stats.md) (/FallibleInc/security-guide-for-developers/blob/master/vulnerabilities-stats.md) vulnerabilities-stats.md        (vulnerabilities-stats.md) (/FallibleInc/security-guide-for-developers/blob/master/vulnerabilities-stats.md) vulnerabilities-stats.md      (Fixed typos) (/FallibleInc/security-guide-for-developers/commit/594165fde13b361de3e53eee96c4fa69c65ff063) Fixed typos    (Jul 22, 2016, 11:15 AM UTC) Jul 22, 2016      (what-can-go-wrong.md) (/FallibleInc/security-guide-for-developers/blob/master/what-can-go-wrong.md) what-can-go-wrong.md        (what-can-go-wrong.md) (/FallibleInc/security-guide-for-developers/blob/master/what-can-go-wrong.md) what-can-go-wrong.md      (adding preface draft (what can go wrong)) (/FallibleInc/security-guide-for-developers/commit/e67255e2a8fb6059171daa5735238cafba99f637) adding preface draft (what can go wrong)    (Nov 22, 2016, 6:28 AM UTC) Nov 22, 2016    View all files       Repository files navigation    README         A practical security guide for web developers (Work in progress)     The intended audience     Security issues happen for two reasons - Developers who have just started and cannot really tell a difference between using MD5 or bcrypt. Developers who know stuff but forget/ignore them.  Our detailed explanations should help the first type while we hope our checklist helps the second one create more secure systems. This is by no means a comprehensive guide, it just covers stuff based on the most common issues we have discovered in the past. Contents     (/FallibleInc/security-guide-for-developers/blob/master/security-checklist.md) The Security Checklist  (/FallibleInc/security-guide-for-developers/blob/master/what-can-go-wrong.md) What can go wrong?  (/FallibleInc/security-guide-for-developers/blob/master/https.md) Securely transporting stuff: HTTPS explained  Authentication: I am who I say I am4.1 Form based authentication4.2 Basic authentication4.3 One is not enough, 2 factor, 3 factor, ....4.4 Why use insecure text messages? Introducing HOTP & TOTP4.5 Handling password resets Authorization: What am I allowed to do?5.1 Token based Authorization5.2 OAuth & OAuth25.3 JWT Data Validation and Sanitation: Never trust user input6.1 Validating and Sanitizing Inputs6.2 Sanitizing Outputs6.3 Cross Site Scripting6.4 Injection Attacks6.5 User uploads6.6 Tamper-proof user inputs Plaintext != Encoding != Encryption != Hashing7.1 Common encoding schemes7.2 Encryption7.3 Hashing & One way functions7.4 Hashing speeds cheatsheet Passwords: dadada, 123456 and cute@1238.1 Password policies8.2 Storing passwords8.3 Life without passwords Public Key Cryptography Sessions: Remember me, please10.1 Where to save state?10.2 Invalidating sessions10.3 Cookie monster & you Fixing security, one header at a time11.1 Secure web headers11.2 Data integrity check for 3rd party code11.3 Certificate Pinning Configuration mistakes12.1 Provisioning in cloud: Ports, Shodan & AWS12.2 Honey, you left the debug mode on12.3 Logging (or not logging)12.4 Monitoring12.5 Principle of least privilege12.6 Rate limiting & Captchas12.7 Storing project secrets and passwords in a file12.8 DNS: Of subdomains and forgotten pet-projects12.9 Patching & Updates Attacks: When the bad guys arrive13.1 Clickjacking13.2 Cross Site Request Forgery13.3 Denial of Service13.4 Server Side Request Forgery (/FallibleInc/security-guide-for-developers/blob/master/vulnerabilities-stats.md) Stats about vulnerabilities discovered in Internet Companies  On reinventing the wheel, and making it square15.1 Security libraries and packages for Python15.2 Security libraries and packages for Node/JS15.3 Learning resources Maintaining a good security hygiene Security Vs Usability Back to Square 1: The Security Checklist explained  Who are we?     We are full stack developers who just grew tired of watching how developers were lowering the barrier to call something a hack by writing unsecure code. In the past six months, we have prevented leaks of more than 15 million credit card details, personal details of over 45 million users and potentially saved companies from shutting down. Recently, we discovered an issue that could result in system takeover and data leak in a bitcoin institution. We have helped several startups secure their systems, most of them for free, sometimes without even getting a thank you in response :) If you disagree with something or find a bug please open an issue or file a PR. Alternatively, you can talk to us on (mailto:hello@fallible.co) hello@fallible.co           (7OXpmqnqODF+gFwhzgd72ifif3A98/wLnR6/JTPY4Uj9OoTnTrZX2sRqzL6iO4b9HxLK/0kcyFxH0zs0f6MpLQ==)  About Security Guide for Developers (\u5b9e\u7528\u6027\u5f00\u53d1\u4eba\u5458\u5b89\u5168\u987b\u77e5)    (https://git.io/security) (https://git.io/security) git.io/security   Topics (/topics/api) (Topic: api) api  (/topics/security) (Topic: security) security  (/topics/books) (Topic: books) books  (/topics/security-checklist) (Topic: security-checklist) security-checklist  (/topics/security-book) (Topic: security-book) security-book    Resources   Readme    (/FallibleInc/security-guide-for-developers/activity)   Activity   (/FallibleInc/security-guide-for-developers/custom-properties)   Custom properties   Stars (/FallibleInc/security-guide-for-developers/stargazers)   20.9k stars  Watchers (/FallibleInc/security-guide-for-developers/watchers)   1.1k watching  Forks (/FallibleInc/security-guide-for-developers/forks)   1.6k forks  (/contact/report-content?content_url=https%3A%2F%2Fgithub.com%2FFallibleInc%2Fsecurity-guide-for-developers&report=FallibleInc+%28user%29) Report repository      (/FallibleInc/security-guide-for-developers/releases) Releases  No releases published   (/orgs/FallibleInc/packages?repo_name=security-guide-for-developers) Packages (0) 0   No packages published       (/FallibleInc/security-guide-for-developers/graphs/contributors) Contributors (23) 23   (https://github.com/mkagenius) (@mkagenius)   (https://github.com/abhishek-anand) (@abhishek-anand)   (https://github.com/jiacheo) (@jiacheo)   (https://github.com/eryno) (@eryno)   (https://github.com/TomCorwine) (@TomCorwine)   (https://github.com/leozhang2018) (@leozhang2018)   (https://github.com/intchloe) (@intchloe)   (https://github.com/paulschreiber) (@paulschreiber)   (https://github.com/Primigenus) (@Primigenus)   (https://github.com/dmcgill50) (@dmcgill50)   (https://github.com/mmattice) (@mmattice)   (https://github.com/bungoume) (@bungoume)   (https://github.com/thijzert) (@thijzert)   (https://github.com/vassudanagunta) (@vassudanagunta)    (/FallibleInc/security-guide-for-developers/graphs/contributors) + 9 contributors              Footer (GitHub) (https://github.com)    \u00a9 2025 GitHub,\u00a0Inc.   Footer navigation (https://docs.github.com/site-policy/github-terms/github-terms-of-service) Terms  (https://docs.github.com/site-policy/privacy-policies/github-privacy-statement) Privacy  (https://github.com/security) Security  (https://www.githubstatus.com/) Status  (https://docs.github.com/) Docs  (https://support.github.com?tags=dotcom-footer) Contact  Manage cookies    Do not share my personal information              You can\u2019t perform that action at this time.         "
                ],
                "output": "htmltotext.txt",
                "pwd": "/data/archive/1736015745.600104",
                "schema": "ArchiveResult",
                "start_ts": "2025-01-04T18:39:45.801951+00:00",
                "status": "succeeded"
            }
        ],
        "media": [
            {
                "cmd": [
                    "/usr/local/bin/yt-dlp",
                    "--restrict-filenames",
                    "--trim-filenames",
                    "128",
                    "--write-description",
                    "--write-info-json",
                    "--write-annotations",
                    "--write-thumbnail",
                    "--no-call-home",
                    "--write-sub",
                    "--write-auto-subs",
                    "--convert-subs=srt",
                    "--yes-playlist",
                    "--continue",
                    "--no-abort-on-error",
                    "--ignore-errors",
                    "--geo-bypass",
                    "--add-metadata",
                    "--format=(bv*+ba/b)[filesize<=750m][filesize_approx<=?750m]/(bv*+ba/b)",
                    "--skip-download",
                    "--cache-dir=/data/yt-dlp-cache/",
                    "--cookies=/data/yt-dlp-cache/cookies.txt",
                    "--proxy=socks5://tor-socks-proxy:9150",
                    "--no-playlist",
                    "https://github.com/FallibleInc/security-guide-for-developers"
                ],
                "cmd_version": "2024.10.7",
                "end_ts": "2025-01-04T18:39:52.488297+00:00",
                "index_texts": [],
                "output": "media/",
                "pwd": "/data/archive/1736015745.600104",
                "schema": "ArchiveResult",
                "start_ts": "2025-01-04T18:39:46.483399+00:00",
                "status": "succeeded"
            }
        ],
        "mercury": [
            {
                "cmd": [
                    "/home/archivebox/.npm/bin/postlight-parser",
                    "https://github.com/FallibleInc/security-guide-for-developers"
                ],
                "cmd_version": "2.2.3",
                "end_ts": "2025-01-04T18:39:45.725476+00:00",
                "index_texts": null,
                "output": "mercury/",
                "pwd": "/data/archive/1736015745.600104",
                "schema": "ArchiveResult",
                "start_ts": "2025-01-04T18:39:36.290746+00:00",
                "status": "succeeded"
            }
        ],
        "pdf": [],
        "readability": [
            {
                "cmd": [
                    "/home/archivebox/.npm/bin/readability-extractor",
                    "/tmp/tmphdns4jki",
                    "https://github.com/FallibleInc/security-guide-for-developers"
                ],
                "cmd_version": "0.0.11",
                "end_ts": "2025-01-04T18:39:36.207713+00:00",
                "index_texts": [
                    "A practical security guide for web developers (Work in progress)\nThe intended audience\nSecurity issues happen for two reasons -\n\nDevelopers who have just started and cannot really tell a difference between using MD5 or bcrypt.\nDevelopers who know stuff but forget/ignore them.\n\nOur detailed explanations should help the first type while we hope our checklist helps the second one create more secure systems. This is by no means a comprehensive guide, it just covers stuff based on the most common issues we have discovered in the past.\nContents\n\nThe Security Checklist\nWhat can go wrong?\nSecurely transporting stuff: HTTPS explained\nAuthentication: I am who I say I am\n4.1 Form based authentication\n4.2 Basic authentication\n4.3 One is not enough, 2 factor, 3 factor, ....\n4.4 Why use insecure text messages? Introducing HOTP & TOTP\n4.5 Handling password resets\nAuthorization: What am I allowed to do?\n5.1 Token based Authorization\n5.2 OAuth & OAuth2\n5.3 JWT\nData Validation and Sanitation: Never trust user input\n6.1 Validating and Sanitizing Inputs\n6.2 Sanitizing Outputs\n6.3 Cross Site Scripting\n6.4 Injection Attacks\n6.5 User uploads\n6.6 Tamper-proof user inputs\nPlaintext != Encoding != Encryption != Hashing\n7.1 Common encoding schemes\n7.2 Encryption\n7.3 Hashing & One way functions\n7.4 Hashing speeds cheatsheet\nPasswords: dadada, 123456 and cute@123\n8.1 Password policies\n8.2 Storing passwords\n8.3 Life without passwords\nPublic Key Cryptography\nSessions: Remember me, please\n10.1 Where to save state?\n10.2 Invalidating sessions\n10.3 Cookie monster & you\nFixing security, one header at a time\n11.1 Secure web headers\n11.2 Data integrity check for 3rd party code\n11.3 Certificate Pinning\nConfiguration mistakes\n12.1 Provisioning in cloud: Ports, Shodan & AWS\n12.2 Honey, you left the debug mode on\n12.3 Logging (or not logging)\n12.4 Monitoring\n12.5 Principle of least privilege\n12.6 Rate limiting & Captchas\n12.7 Storing project secrets and passwords in a file\n12.8 DNS: Of subdomains and forgotten pet-projects\n12.9 Patching & Updates\nAttacks: When the bad guys arrive\n13.1 Clickjacking\n13.2 Cross Site Request Forgery\n13.3 Denial of Service\n13.4 Server Side Request Forgery\nStats about vulnerabilities discovered in Internet Companies\nOn reinventing the wheel, and making it square\n15.1 Security libraries and packages for Python\n15.2 Security libraries and packages for Node/JS\n15.3 Learning resources\nMaintaining a good security hygiene\nSecurity Vs Usability\nBack to Square 1: The Security Checklist explained\n\nWho are we?\nWe are full stack developers who just grew tired of watching how developers were lowering the barrier to call something a hack by writing unsecure code. In the past six months, we have prevented leaks of more than 15 million credit card details, personal details of over 45 million users and potentially saved companies from shutting down. Recently, we discovered an issue that could result in system takeover and data leak in a bitcoin institution. We have helped several startups secure their systems, most of them for free, sometimes without even getting a thank you in response :)\nIf you disagree with something or find a bug please open an issue or file a PR. Alternatively, you can talk to us on hello@fallible.co"
                ],
                "output": "readability/",
                "pwd": "/data/archive/1736015745.600104",
                "schema": "ArchiveResult",
                "start_ts": "2025-01-04T18:39:27.817530+00:00",
                "status": "succeeded"
            }
        ],
        "screenshot": [],
        "singlefile": [],
        "title": [
            {
                "cmd": [
                    "/usr/bin/curl",
                    "--silent",
                    "--location",
                    "--compressed",
                    "--proxy",
                    "socks5://tor-socks-proxy:9150",
                    "--max-time",
                    "60",
                    "--user-agent",
                    "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36 ArchiveBox/{VERSION} (+https://github.com/ArchiveBox/ArchiveBox/)",
                    "https://github.com/FallibleInc/security-guide-for-developers"
                ],
                "cmd_version": "8.10.1",
                "end_ts": "2025-01-04T18:39:27.665419+00:00",
                "index_texts": null,
                "output": "GitHub - FallibleInc/security-guide-for-developers: Security Guide for Developers (\u5b9e\u7528\u6027\u5f00\u53d1\u4eba\u5458\u5b89\u5168\u987b\u77e5)",
                "pwd": "/data/archive/1736015745.600104",
                "schema": "ArchiveResult",
                "start_ts": "2025-01-04T18:39:27.520754+00:00",
                "status": "succeeded"
            }
        ],
        "wget": []
    },
    "icons": null,
    "is_archived": true,
    "is_static": false,
    "latest": {
        "archive_org": "ArchiveError: Failed to find \"content-location\" URL header in Archive.org response.",
        "dom": "output.html",
        "favicon": "favicon.ico",
        "git": null,
        "media": "media/",
        "pdf": null,
        "screenshot": null,
        "singlefile": null,
        "title": "GitHub - FallibleInc/security-guide-for-developers: Security Guide for Developers (\u5b9e\u7528\u6027\u5f00\u53d1\u4eba\u5458\u5b89\u5168\u987b\u77e5)",
        "warc": null,
        "wget": null
    },
    "link_dir": "/data/archive/1736015745.600104",
    "newest_archive_date": "2025-01-04T18:39:52.529207+00:00",
    "num_failures": 1,
    "num_outputs": 8,
    "oldest_archive_date": "2025-01-04T18:39:11.067831+00:00",
    "path": "/FallibleInc/security-guide-for-developers",
    "schema": "Link",
    "scheme": "https",
    "snapshot_abid": "snp_01JGS9M56Q1039DB3201X1FW53",
    "snapshot_id": "09881e94-3ae3-407b-a66f-38b27a17f0a3",
    "sources": [
        "/data/sources/1736015744-import.txt"
    ],
    "tags": null,
    "tags_str": "",
    "timestamp": "1736015745.600104",
    "title": "GitHub - FallibleInc/security-guide-for-developers: Security Guide for Developers (\u5b9e\u7528\u6027\u5f00\u53d1\u4eba\u5458\u5b89\u5168\u987b\u77e5)",
    "url": "https://github.com/FallibleInc/security-guide-for-developers"
}