SDL and Web 2.0
...functionality of a banks web site, or the security trading functionality of a brokerage firms web site
So, what does the SDL have to say about these issues? In terms of XSS prevention, the SDL offers a lot of guidance. The SDL requires the use of both input validation (making sure that user input conforms to a known good format in the case of...
