<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>安全知識庫 | MoShield</title><link>https://moshieldapp.com/zh-tw/blog/</link><description>為中小企業提供實用的網站與 API 安全知識，協助確認檢測範圍、理解風險並推動改善。</description><language>zh-TW</language><item><title>中小企業網站安全檢查清單：從哪裡開始？</title><link>https://moshieldapp.com/zh-tw/blog/website-security-checklist/</link><guid>https://moshieldapp.com/zh-tw/blog/website-security-checklist/</guid><pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate><description>先列清公開服務、處理的資料和負責人，再決定檢測範圍。安全檢查的成果應是可分派、可驗證的改善工作，而不只是一個掃描分數。</description></item><item><title>黑箱安全檢測與漏洞掃描有何不同？</title><link>https://moshieldapp.com/zh-tw/blog/black-box-testing-vs-scanning/</link><guid>https://moshieldapp.com/zh-tw/blog/black-box-testing-vs-scanning/</guid><pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate><description>黑箱描述測試人員掌握多少系統內部資訊；掃描是一種檢查技術。一次限定範圍的評估可以同時採用自動化與人工分析。</description></item><item><title>網站安全檢測前要準備哪些授權資料？</title><link>https://moshieldapp.com/zh-tw/blog/prepare-authorized-security-test/</link><guid>https://moshieldapp.com/zh-tw/blog/prepare-authorized-security-test/</guid><pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate><description>開始前先約定資產、允許操作、時間窗口及緊急聯絡人。明確計畫能協助雙方在異常時停止，而不是臨時猜測。</description></item><item><title>API 權限檢查：為什麼登入成功仍不夠？</title><link>https://moshieldapp.com/zh-tw/blog/api-object-authorization/</link><guid>https://moshieldapp.com/zh-tw/blog/api-object-authorization/</guid><pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate><description>身分驗證確認使用者是誰，物件層級授權決定他能否存取特定記錄。客戶 API 需要同時處理兩者。</description></item><item><title>聯絡表單的 PDF 和圖片附件如何安全保存？</title><link>https://moshieldapp.com/zh-tw/blog/secure-file-upload-forms/</link><guid>https://moshieldapp.com/zh-tw/blog/secure-file-upload-forms/</guid><pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate><description>附件應視為不可信資料。檔案驗證、私有儲存和受控讀取各有用途，只限制副檔名並不足夠。</description></item><item><title>登入安全：除了密碼，也要檢查帳號復原</title><link>https://moshieldapp.com/zh-tw/blog/login-security-basics/</link><guid>https://moshieldapp.com/zh-tw/blog/login-security-basics/</guid><pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate><description>登入審查需要涵蓋帳號復原和敏感變更。主要登入很強，仍可能被較弱的復原管道破壞。</description></item><item><title>有 HTTPS 就安全嗎？憑證不等於安全檢測</title><link>https://moshieldapp.com/zh-tw/blog/https-is-not-a-security-audit/</link><guid>https://moshieldapp.com/zh-tw/blog/https-is-not-a-security-audit/</guid><pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate><description>HTTPS 保護傳輸中的通訊，並不決定客戶是否有權查看別人的記錄，或附件是否以私有方式保存。</description></item><item><title>安全漏洞先修哪個？小團隊的排序方法</title><link>https://moshieldapp.com/zh-tw/blog/prioritize-security-fixes/</link><guid>https://moshieldapp.com/zh-tw/blog/prioritize-security-fixes/</guid><pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate><description>結合技術證據和業務背景安排修復。嚴重程度是討論起點，不能代替對暴露範圍和修復責任的了解。</description></item><item><title>企業負責人如何讀懂網站安全報告？</title><link>https://moshieldapp.com/zh-tw/blog/read-a-security-report/</link><guid>https://moshieldapp.com/zh-tw/blog/read-a-security-report/</guid><pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate><description>先讀範圍和限制，再看問題數量。接著區分業務決策、工程修改與仍需解釋的事項。</description></item><item><title>漏洞修好後為何還要複測？</title><link>https://moshieldapp.com/zh-tw/blog/security-retesting-after-fixes/</link><guid>https://moshieldapp.com/zh-tw/blog/security-retesting-after-fixes/</guid><pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate><description>修復應在實際相關環境中驗證。複測既確認原問題得到處理，也確認合法使用者仍能完成正常工作。</description></item></channel></rss>