This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org
Difference between revisions of "OWASP Java Project WIPRO 1 2015"
From OWASP
m (→Classifications) |
m |
||
Line 14: | Line 14: | ||
| valign="top" style="border-right: 1px dotted gray;padding-right:25px;width:100%" | | | valign="top" style="border-right: 1px dotted gray;padding-right:25px;width:100%" | | ||
− | + | 91 Pages in category "OWASP Java Project" to be reviewed. | |
+ | {| class="wikitable" | ||
+ | ! Page | ||
+ | ! Review | ||
+ | ! Decision | ||
+ | ! Comments | ||
+ | |- | ||
+ | |[[Bytecode obfuscation]] | ||
+ | | | ||
+ | | | ||
+ | | | ||
+ | |- | ||
+ | |[[Captchas in Java ]] | ||
+ | | | ||
+ | | | ||
+ | | | ||
+ | |- | ||
+ | |[[Clickjacking Protection for Java EE]] | ||
+ | | | ||
+ | | | ||
+ | | | ||
+ | |- | ||
+ | |[[Command injection in Java]] | ||
+ | | | ||
+ | | | ||
+ | | | ||
+ | |- | ||
+ | |[[Comparing classes by name ]] | ||
+ | | | ||
+ | | | ||
+ | | | ||
+ | |- | ||
+ | |[[Complejidad Y Longitud De Las Contraseñas ]] | ||
+ | | | ||
+ | | | ||
+ | | | ||
+ | |- | ||
+ | |[[Content Security Policy ]] | ||
+ | | | ||
+ | | | ||
+ | | | ||
+ | |- | ||
+ | |[[CORS OriginHeaderScrutiny]] | ||
+ | | | ||
+ | | | ||
+ | | | ||
+ | |- | ||
+ | |[[CORS RequestPreflighScrutiny]] | ||
+ | | | ||
+ | | | ||
+ | | | ||
+ | |- | ||
+ | |[[Cross-site Scripting (XSS) ]] | ||
+ | | | ||
+ | | | ||
+ | | | ||
+ | |- | ||
+ | |[[Declarative Access Control in Java]] | ||
+ | | | ||
+ | | | ||
+ | | | ||
+ | |- | ||
+ | |[[Decompiling Java bytecode]] | ||
+ | | | ||
+ | | | ||
+ | | | ||
+ | |- | ||
+ | |[[Deserialization of untrusted data]] | ||
+ | | | ||
+ | | | ||
+ | | | ||
+ | |- | ||
+ | |[[Detect profiling phase into web application]] | ||
+ | | | ||
+ | | | ||
+ | | | ||
+ | |- | ||
+ | |[[Digital Signature Implementation in Java]] | ||
+ | | | ||
+ | | | ||
+ | | | ||
+ | |- | ||
+ | |[[Exception handling techniques ]] | ||
+ | | | ||
+ | | | ||
+ | | | ||
+ | |- | ||
+ | |[[Failure to follow guideline/specification ]] | ||
+ | | | ||
+ | | | ||
+ | | | ||
+ | |- | ||
+ | |[[Hacking Java Clients ]] | ||
+ | | | ||
+ | | | ||
+ | | | ||
+ | |- | ||
+ | |[[Hashing Java]] | ||
+ | | | ||
+ | | | ||
+ | | | ||
+ | |- | ||
+ | |[[Hibernate]] | ||
+ | | | ||
+ | | | ||
+ | | | ||
+ | |- | ||
+ | |[[Hibernate-Guidelines ]] | ||
+ | | | ||
+ | | | ||
+ | | | ||
+ | |- | ||
+ | |[[How to add validation logic to HttpServletRequest]] | ||
+ | | | ||
+ | | | ||
+ | | | ||
+ | |- | ||
+ | |[[How to encrypt a properties file ]] | ||
+ | | | ||
+ | | | ||
+ | | | ||
+ | |- | ||
+ | |[[Implementacion De Firmas Digitales en Java]] | ||
+ | | | ||
+ | | | ||
+ | | | ||
+ | |- | ||
+ | |[[Improper Data Validation]] | ||
+ | | | ||
+ | | | ||
+ | | | ||
+ | |- | ||
+ | |[[Improper temp file opening ]] | ||
+ | | | ||
+ | | | ||
+ | | | ||
+ | |- | ||
+ | |[[Information Leakage]] | ||
+ | | | ||
+ | | | ||
+ | | | ||
+ | |- | ||
+ | |[[Insecure Randomness]] | ||
+ | | | ||
+ | | | ||
+ | | | ||
+ | |- | ||
+ | |[[Insecure Transport]] | ||
+ | | | ||
+ | | | ||
+ | | | ||
+ | |- | ||
+ | |[[Insufficient Session-ID Length]] | ||
+ | | | ||
+ | | | ||
+ | | | ||
+ | |- | ||
+ | |[[Invoking untrusted mobile code]] | ||
+ | | | ||
+ | | | ||
+ | | | ||
+ | |- | ||
+ | |[[Inyección De Comandos En Java ]] | ||
+ | | | ||
+ | | | ||
+ | | | ||
+ | |- | ||
+ | |[[J2EE Misconfiguration: Unsafe Bean Declaration]] | ||
+ | | | ||
+ | | | ||
+ | | | ||
+ | |- | ||
+ | |[[J2EE third party libraries insecurity]] | ||
+ | | | ||
+ | | | ||
+ | | | ||
+ | |- | ||
+ | |[[JAAS Timed Login Module ]] | ||
+ | | | ||
+ | | | ||
+ | | | ||
+ | |- | ||
+ | |[[JAAS Tomcat Login Module]] | ||
+ | | | ||
+ | | | ||
+ | | | ||
+ | |- | ||
+ | |[[Java Project Article Wishlist ]] | ||
+ | | | ||
+ | | | ||
+ | | | ||
+ | |- | ||
+ | |[[Java Security Frameworks]] | ||
+ | | | ||
+ | | | ||
+ | | | ||
+ | |- | ||
+ | |[[Java Security Resources ]] | ||
+ | | | ||
+ | | | ||
+ | | | ||
+ | |- | ||
+ | |[[Java Server Faces ]] | ||
+ | | | ||
+ | | | ||
+ | | | ||
+ | |- | ||
+ | |[[JSP errorPage]] | ||
+ | | | ||
+ | | | ||
+ | | | ||
+ | |- | ||
+ | |[[JSP JSTL ]] | ||
+ | | | ||
+ | | | ||
+ | | | ||
+ | |- | ||
+ | |[[Leftover Debug Code]] | ||
+ | | | ||
+ | | | ||
+ | | | ||
+ | |- | ||
+ | |[[Log Forging ]] | ||
+ | | | ||
+ | | | ||
+ | | | ||
+ | |- | ||
+ | |[[Logout]] | ||
+ | | | ||
+ | | | ||
+ | | | ||
+ | |- | ||
+ | |[[Member Field Race Condition]] | ||
+ | | | ||
+ | | | ||
+ | | | ||
+ | |- | ||
+ | |[[Missing Error Handling]] | ||
+ | | | ||
+ | | | ||
+ | | | ||
+ | |- | ||
+ | |[[Mobile Java Security ]] | ||
+ | | | ||
+ | | | ||
+ | | | ||
+ | |- | ||
+ | |[[Null Dereference]] | ||
+ | | | ||
+ | | | ||
+ | | | ||
+ | |- | ||
+ | |[[Object Model Violation: Just One of equals() and hashCode() Defined]] | ||
+ | | | ||
+ | | | ||
+ | | | ||
+ | |- | ||
+ | |[[Often Misused: Authentication ]] | ||
+ | | | ||
+ | | | ||
+ | | | ||
+ | |- | ||
+ | |[[Overly-Broad Catch Block]] | ||
+ | | | ||
+ | | | ||
+ | | | ||
+ | |- | ||
+ | |[[Overly-Broad Throws Declaration]] | ||
+ | | | ||
+ | | | ||
+ | | | ||
+ | |- | ||
+ | |[[OWASP CSRFGuard Project/es ]] | ||
+ | | | ||
+ | | | ||
+ | | | ||
+ | |- | ||
+ | |[[OWASP Java Table of Contents]] | ||
+ | | | ||
+ | | | ||
+ | | | ||
+ | |- | ||
+ | |[[Parameter Validation Filter]] | ||
+ | | | ||
+ | | | ||
+ | | | ||
+ | |- | ||
+ | |[[Password length & complexity]] | ||
+ | | | ||
+ | | | ||
+ | | | ||
+ | |- | ||
+ | |[[Password Management: Hardcoded Password]] | ||
+ | | | ||
+ | | | ||
+ | | | ||
+ | |- | ||
+ | |[[Password Management: Weak Cryptography ]] | ||
+ | | | ||
+ | | | ||
+ | | | ||
+ | |- | ||
+ | |[[Password Plaintext Storage ]] | ||
+ | | | ||
+ | | | ||
+ | | | ||
+ | |- | ||
+ | |[[PDF Attack Filter for Java EE ]] | ||
+ | | | ||
+ | | | ||
+ | | | ||
+ | |- | ||
+ | |[[Poor Logging Practice]] | ||
+ | | | ||
+ | | | ||
+ | | | ||
+ | |- | ||
+ | |[[Preventing LDAP Injection in Java]] | ||
+ | | | ||
+ | | | ||
+ | | | ||
+ | |- | ||
+ | |[[Preventing SQL Injection in Java ]] | ||
+ | | | ||
+ | | | ||
+ | | | ||
+ | |- | ||
+ | |[[Process Control]] | ||
+ | | | ||
+ | | | ||
+ | | | ||
+ | |- | ||
+ | |[[Protecting code archives with digital signatures]] | ||
+ | | | ||
+ | | | ||
+ | | | ||
+ | |- | ||
+ | |[[Reflection attack in an auth protocol]] | ||
+ | | | ||
+ | | | ||
+ | | | ||
+ | |- | ||
+ | |[[Return Inside Finally Block]] | ||
+ | | | ||
+ | | | ||
+ | | | ||
+ | |- | ||
+ | |[[Securing tomcat]] | ||
+ | | | ||
+ | | | ||
+ | | | ||
+ | |- | ||
+ | |[[Servlet spec - web.xml]] | ||
+ | | | ||
+ | | | ||
+ | | | ||
+ | |- | ||
+ | |[[Session Fixation]] | ||
+ | | | ||
+ | | | ||
+ | | | ||
+ | |- | ||
+ | |[[Session Timeout]] | ||
+ | | | ||
+ | | | ||
+ | | | ||
+ | |- | ||
+ | |[[Signing jar files with jarsigner ]] | ||
+ | | | ||
+ | | | ||
+ | | | ||
+ | |- | ||
+ | |[[State synchronization error]] | ||
+ | | | ||
+ | | | ||
+ | | | ||
+ | |- | ||
+ | |[[Struts]] | ||
+ | | | ||
+ | | | ||
+ | | | ||
+ | |- | ||
+ | |[[Struts Validation in an ActionForm]] | ||
+ | | | ||
+ | | | ||
+ | | | ||
+ | |- | ||
+ | |[[Struts Validation in validator.xml using an ActionForm]] | ||
+ | | | ||
+ | | | ||
+ | | | ||
+ | |- | ||
+ | |[[Struts XSLT Viewer]] | ||
+ | | | ||
+ | | | ||
+ | | | ||
+ | |- | ||
+ | |[[Traducción Español]] | ||
+ | | | ||
+ | | | ||
+ | | | ||
+ | |- | ||
+ | |[[Trust Boundary Violation]] | ||
+ | | | ||
+ | | | ||
+ | | | ||
+ | |- | ||
+ | |[[Trustworthy Java]] | ||
+ | | | ||
+ | | | ||
+ | | | ||
+ | |- | ||
+ | |[[Uncaught exception]] | ||
+ | | | ||
+ | | | ||
+ | | | ||
+ | |- | ||
+ | |[[Unchecked Return Value: Missing Check against Null ]] | ||
+ | | | ||
+ | | | ||
+ | | | ||
+ | |- | ||
+ | |[[Unreleased Resource]] | ||
+ | | | ||
+ | | | ||
+ | | | ||
+ | |- | ||
+ | |[[Unsafe JNI]] | ||
+ | | | ||
+ | | | ||
+ | | | ||
+ | |- | ||
+ | |[[Unsafe Mobile Code]] | ||
+ | | | ||
+ | | | ||
+ | | | ||
+ | |- | ||
+ | |[[Unsafe Reflection ]] | ||
+ | | | ||
+ | | | ||
+ | | | ||
+ | |- | ||
+ | |[[Using JCaptcha ]] | ||
+ | | | ||
+ | | | ||
+ | | | ||
+ | |- | ||
+ | |[[Using the Java Cryptographic Extensions]] | ||
+ | | | ||
+ | | | ||
+ | | | ||
+ | |- | ||
+ | |[[Using the Java Secure Socket Extensions]] | ||
+ | | | ||
+ | | | ||
+ | | | ||
+ | |- | ||
+ | |[[XPATH Injection Java ]] | ||
+ | | | ||
+ | | | ||
+ | | | ||
+ | |} | ||
| valign="top" style="padding-left:25px;min-width:200px;border-right: 1px dotted gray;padding-right:25px;" | | | valign="top" style="padding-left:25px;min-width:200px;border-right: 1px dotted gray;padding-right:25px;" | |
Revision as of 08:55, 14 December 2015
Wiki Pages Review Operation - 2015/2016
OWASP Java and JVM Project - Wiki Pages Review Operation 1 - 2015/2016
PROJECT INFO What does this OWASP project offer you? |
RELEASE(S) INFO What releases are available for this project? | |||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|