Difference between revisions of "Category:OWASP Java Project"
|Line 25:||Line 25:|
Revision as of 10:25, 25 May 2006
While Java and J2EE contain many security technologies, it is not easy to produce an application without security vulnerabilities. Most application security Vulnerabilities apply to Java applications just like other environments. The notable exception is buffer overflow and related issues that do not apply to Java applications.
Securing the Java Environment
Verifier and Sandbox JRE vs. JDK (precompile JSPs)
Securing Java Application Code
Common vulnerabilities like...Runtime.exec, Statement, readline() Dangers of native code, dynamic code, and reflection Tools like PMD and FindBugs Security mechanisms like logging, encryption, error handling
Securing the J2EE Environment
Minimize attack surface in web.xml Configure error handlers
Securing J2EE Application Code
Vulnerabilities like... Using J2EE filters for protection Mechanisms like input validation, encoding Common vulnerabilities like...
Pages in category "OWASP Java Project"
The following 30 pages are in this category, out of 30 total.
Media in category "OWASP Java Project"
This category contains only the following file.