Twelve Java Technology Security Traps and How to Avoid Them
File Size:
KB
Developer:
Description:
This session doesnt include a review of 10-year-old guidelines for writing secure applets with JDK 1.1 software. Instead, it looks at causes of security failures in modern Java technology-based applications. Approaching security with an outside in style like that of the OWASP Top 10, it looks at vulnerabilities from a developers perspective, focusing on the source code. It looks at examples of real vulnerabilities in Tomcat and widely deployed blogging packages such as Blojsom and explores how the problems facing web-based applications are made worse by the transition to a service-oriented architecture.