Get the Whitepaper called Enough With Default Allow in Web Applications.
You can download it from the following link: https://packetstormsecurity.com/files/download/95377/default-allow.pdf
Source: https://packetstormsecurity.com/files/95377/Enough-With-Default-Allow-In-Web-Applications.html

