You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
 
 
 
 
 
 
nprimo 29b2fc9d6f fix: update broken links in `audit/README.md` files 1 year ago
..
audit fix: update broken links in `audit/README.md` files 1 year ago
README.md fix(projects): replace satori/uuid in some projects because it is unmaintained and vulnurable 2 years ago
audit.md feat(audit.md): restore old audit.md files 1 year ago

README.md

forum-security

Objectives

You must follow the same principles as the first subject.

For this project you must take into account the security of your forum.

  • You should implement a Hypertext Transfer Protocol Secure (HTTPS) protocol :

    • Encrypted connection : for this you will have to generate an SSL certificate, you can think of this like a identity card for your website. You can create your certificates or use "Certificate Authorities"(CA's)

    • We recommend you to take a look into cipher suites.

  • The implementation of Rate Limiting must be present on this project

  • You should encrypt at least the clients passwords. As a Bonus you can also encrypt the database, for this you will have to create a password for your database.

Sessions and cookies were implemented in the previous project but not under-pressure (tested in an attack environment). So this time you must take this into account.

  • Clients session cookies should be unique. For instance, the session state is stored on the server and the session should present an unique identifier. This way the client has no direct access to it. Therefore, there is no way for attackers to read or tamper with session state.

Hints

Instructions

  • You must handle website errors, HTTPS status.
  • You must handle all sort of technical errors.
  • The code must respect the good practices.
  • It is recommended to have test files for unit testing.

Allowed packages

This project will help you learn about :

  • HTTPS
  • Cipher suites
  • Goroutines
  • Channels
  • Rate Limiting
  • Encryption
    • password
    • session/cookies
    • Universal Unique Identifier (UUID)