This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org

Difference between revisions of "OWASP Java Project WIPRO 1 2015"

From OWASP
Jump to: navigation, search
m (Classifications)
m
Line 14: Line 14:
 
| valign="top" style="border-right: 1px dotted gray;padding-right:25px;width:100%" |
 
| valign="top" style="border-right: 1px dotted gray;padding-right:25px;width:100%" |
  
...
+
91 Pages in category "OWASP Java Project" to be reviewed.  
  
 +
{| class="wikitable"
 +
! Page
 +
! Review
 +
! Decision
 +
! Comments
 +
|-
 +
|[[Bytecode obfuscation]]
 +
|
 +
|
 +
|
 +
|-
 +
|[[Captchas in Java ]]
 +
|
 +
|
 +
|
 +
|-
 +
|[[Clickjacking Protection for Java EE]]
 +
|
 +
|
 +
|
 +
|-
 +
|[[Command injection in Java]]
 +
|
 +
|
 +
|
 +
|-
 +
|[[Comparing classes by name ]]
 +
|
 +
|
 +
|
 +
|-
 +
|[[Complejidad Y Longitud De Las Contraseñas ]]
 +
|
 +
|
 +
|
 +
|-
 +
|[[Content Security Policy ]]
 +
|
 +
|
 +
|
 +
|-
 +
|[[CORS OriginHeaderScrutiny]]
 +
|
 +
|
 +
|
 +
|-
 +
|[[CORS RequestPreflighScrutiny]]
 +
|
 +
|
 +
|
 +
|-
 +
|[[Cross-site Scripting (XSS) ]]
 +
|
 +
|
 +
|
 +
|-
 +
|[[Declarative Access Control in Java]]
 +
|
 +
|
 +
|
 +
|-
 +
|[[Decompiling Java bytecode]]
 +
|
 +
|
 +
|
 +
|-
 +
|[[Deserialization of untrusted data]]
 +
|
 +
|
 +
|
 +
|-
 +
|[[Detect profiling phase into web application]]
 +
|
 +
|
 +
|
 +
|-
 +
|[[Digital Signature Implementation in Java]]
 +
|
 +
|
 +
|
 +
|-
 +
|[[Exception handling techniques ]]
 +
|
 +
|
 +
|
 +
|-
 +
|[[Failure to follow guideline/specification ]]
 +
|
 +
|
 +
|
 +
|-
 +
|[[Hacking Java Clients ]]
 +
|
 +
|
 +
|
 +
|-
 +
|[[Hashing Java]]
 +
|
 +
|
 +
|
 +
|-
 +
|[[Hibernate]]
 +
|
 +
|
 +
|
 +
|-
 +
|[[Hibernate-Guidelines ]]
 +
|
 +
|
 +
|
 +
|-
 +
|[[How to add validation logic to HttpServletRequest]]
 +
|
 +
|
 +
|
 +
|-
 +
|[[How to encrypt a properties file ]]
 +
|
 +
|
 +
|
 +
|-
 +
|[[Implementacion De Firmas Digitales en Java]]
 +
|
 +
|
 +
|
 +
|-
 +
|[[Improper Data Validation]]
 +
|
 +
|
 +
|
 +
|-
 +
|[[Improper temp file opening ]]
 +
|
 +
|
 +
|
 +
|-
 +
|[[Information Leakage]]
 +
|
 +
|
 +
|
 +
|-
 +
|[[Insecure Randomness]]
 +
|
 +
|
 +
|
 +
|-
 +
|[[Insecure Transport]]
 +
|
 +
|
 +
|
 +
|-
 +
|[[Insufficient Session-ID Length]]
 +
|
 +
|
 +
|
 +
|-
 +
|[[Invoking untrusted mobile code]]
 +
|
 +
|
 +
|
 +
|-
 +
|[[Inyección De Comandos En Java ]]
 +
|
 +
|
 +
|
 +
|-
 +
|[[J2EE Misconfiguration: Unsafe Bean Declaration]]
 +
|
 +
|
 +
|
 +
|-
 +
|[[J2EE third party libraries insecurity]]
 +
|
 +
|
 +
|
 +
|-
 +
|[[JAAS Timed Login Module ]]
 +
|
 +
|
 +
|
 +
|-
 +
|[[JAAS Tomcat Login Module]]
 +
|
 +
|
 +
|
 +
|-
 +
|[[Java Project Article Wishlist ]]
 +
|
 +
|
 +
|
 +
|-
 +
|[[Java Security Frameworks]]
 +
|
 +
|
 +
|
 +
|-
 +
|[[Java Security Resources ]]
 +
|
 +
|
 +
|
 +
|-
 +
|[[Java Server Faces ]]
 +
|
 +
|
 +
|
 +
|-
 +
|[[JSP errorPage]]
 +
|
 +
|
 +
|
 +
|-
 +
|[[JSP JSTL ]]
 +
|
 +
|
 +
|
 +
|-
 +
|[[Leftover Debug Code]]
 +
|
 +
|
 +
|
 +
|-
 +
|[[Log Forging ]]
 +
|
 +
|
 +
|
 +
|-
 +
|[[Logout]]
 +
|
 +
|
 +
|
 +
|-
 +
|[[Member Field Race Condition]]
 +
|
 +
|
 +
|
 +
|-
 +
|[[Missing Error Handling]]
 +
|
 +
|
 +
|
 +
|-
 +
|[[Mobile Java Security ]]
 +
|
 +
|
 +
|
 +
|-
 +
|[[Null Dereference]]
 +
|
 +
|
 +
|
 +
|-
 +
|[[Object Model Violation: Just One of equals() and hashCode() Defined]]
 +
|
 +
|
 +
|
 +
|-
 +
|[[Often Misused: Authentication ]]
 +
|
 +
|
 +
|
 +
|-
 +
|[[Overly-Broad Catch Block]]
 +
|
 +
|
 +
|
 +
|-
 +
|[[Overly-Broad Throws Declaration]]
 +
|
 +
|
 +
|
 +
|-
 +
|[[OWASP CSRFGuard Project/es ]]
 +
|
 +
|
 +
|
 +
|-
 +
|[[OWASP Java Table of Contents]]
 +
|
 +
|
 +
|
 +
|-
 +
|[[Parameter Validation Filter]]
 +
|
 +
|
 +
|
 +
|-
 +
|[[Password length & complexity]]
 +
|
 +
|
 +
|
 +
|-
 +
|[[Password Management: Hardcoded Password]]
 +
|
 +
|
 +
|
 +
|-
 +
|[[Password Management: Weak Cryptography ]]
 +
|
 +
|
 +
|
 +
|-
 +
|[[Password Plaintext Storage ]]
 +
|
 +
|
 +
|
 +
|-
 +
|[[PDF Attack Filter for Java EE ]]
 +
|
 +
|
 +
|
 +
|-
 +
|[[Poor Logging Practice]]
 +
|
 +
|
 +
|
 +
|-
 +
|[[Preventing LDAP Injection in Java]]
 +
|
 +
|
 +
|
 +
|-
 +
|[[Preventing SQL Injection in Java ]]
 +
|
 +
|
 +
|
 +
|-
 +
|[[Process Control]]
 +
|
 +
|
 +
|
 +
|-
 +
|[[Protecting code archives with digital signatures]]
 +
|
 +
|
 +
|
 +
|-
 +
|[[Reflection attack in an auth protocol]]
 +
|
 +
|
 +
|
 +
|-
 +
|[[Return Inside Finally Block]]
 +
|
 +
|
 +
|
 +
|-
 +
|[[Securing tomcat]]
 +
|
 +
|
 +
|
 +
|-
 +
|[[Servlet spec - web.xml]]
 +
|
 +
|
 +
|
 +
|-
 +
|[[Session Fixation]]
 +
|
 +
|
 +
|
 +
|-
 +
|[[Session Timeout]]
 +
|
 +
|
 +
|
 +
|-
 +
|[[Signing jar files with jarsigner ]]
 +
|
 +
|
 +
|
 +
|-
 +
|[[State synchronization error]]
 +
|
 +
|
 +
|
 +
|-
 +
|[[Struts]]
 +
|
 +
|
 +
|
 +
|-
 +
|[[Struts Validation in an ActionForm]]
 +
|
 +
|
 +
|
 +
|-
 +
|[[Struts Validation in validator.xml using an ActionForm]]
 +
|
 +
|
 +
|
 +
|-
 +
|[[Struts XSLT Viewer]]
 +
|
 +
|
 +
|
 +
|-
 +
|[[Traducción Español]]
 +
|
 +
|
 +
|
 +
|-
 +
|[[Trust Boundary Violation]]
 +
|
 +
|
 +
|
 +
|-
 +
|[[Trustworthy Java]]
 +
|
 +
|
 +
|
 +
|-
 +
|[[Uncaught exception]]
 +
|
 +
|
 +
|
 +
|-
 +
|[[Unchecked Return Value: Missing Check against Null ]]
 +
|
 +
|
 +
|
 +
|-
 +
|[[Unreleased Resource]]
 +
|
 +
|
 +
|
 +
|-
 +
|[[Unsafe JNI]]
 +
|
 +
|
 +
|
 +
|-
 +
|[[Unsafe Mobile Code]]
 +
|
 +
|
 +
|
 +
|-
 +
|[[Unsafe Reflection ]]
 +
|
 +
|
 +
|
 +
|-
 +
|[[Using JCaptcha ]]
 +
|
 +
|
 +
|
 +
|-
 +
|[[Using the Java Cryptographic Extensions]]
 +
|
 +
|
 +
|
 +
|-
 +
|[[Using the Java Secure Socket Extensions]]
 +
|
 +
|
 +
|
 +
|-
 +
|[[XPATH Injection Java ]]
 +
|
 +
|
 +
|
 +
|}
  
 
| valign="top"  style="padding-left:25px;min-width:200px;border-right: 1px dotted gray;padding-right:25px;" |
 
| valign="top"  style="padding-left:25px;min-width:200px;border-right: 1px dotted gray;padding-right:25px;" |

Revision as of 08:55, 14 December 2015

OWASP Java Project Header.png


Wiki Pages Review Operation - 2015/2016

OWASP Java Project


91 Pages in category "OWASP Java Project" to be reviewed.

Page Review Decision Comments
Bytecode obfuscation
Captchas in Java
Clickjacking Protection for Java EE
Command injection in Java
Comparing classes by name
Complejidad Y Longitud De Las Contraseñas
Content Security Policy
CORS OriginHeaderScrutiny
CORS RequestPreflighScrutiny
Cross-site Scripting (XSS)
Declarative Access Control in Java
Decompiling Java bytecode
Deserialization of untrusted data
Detect profiling phase into web application
Digital Signature Implementation in Java
Exception handling techniques
Failure to follow guideline/specification
Hacking Java Clients
Hashing Java
Hibernate
Hibernate-Guidelines
How to add validation logic to HttpServletRequest
How to encrypt a properties file
Implementacion De Firmas Digitales en Java
Improper Data Validation
Improper temp file opening
Information Leakage
Insecure Randomness
Insecure Transport
Insufficient Session-ID Length
Invoking untrusted mobile code
Inyección De Comandos En Java
J2EE Misconfiguration: Unsafe Bean Declaration
J2EE third party libraries insecurity
JAAS Timed Login Module
JAAS Tomcat Login Module
Java Project Article Wishlist
Java Security Frameworks
Java Security Resources
Java Server Faces
JSP errorPage
JSP JSTL
Leftover Debug Code
Log Forging
Logout
Member Field Race Condition
Missing Error Handling
Mobile Java Security
Null Dereference
Object Model Violation: Just One of equals() and hashCode() Defined
Often Misused: Authentication
Overly-Broad Catch Block
Overly-Broad Throws Declaration
OWASP CSRFGuard Project/es
OWASP Java Table of Contents
Parameter Validation Filter
Password length & complexity
Password Management: Hardcoded Password
Password Management: Weak Cryptography
Password Plaintext Storage
PDF Attack Filter for Java EE
Poor Logging Practice
Preventing LDAP Injection in Java
Preventing SQL Injection in Java
Process Control
Protecting code archives with digital signatures
Reflection attack in an auth protocol
Return Inside Finally Block
Securing tomcat
Servlet spec - web.xml
Session Fixation
Session Timeout
Signing jar files with jarsigner
State synchronization error
Struts
Struts Validation in an ActionForm
Struts Validation in validator.xml using an ActionForm
Struts XSLT Viewer
Traducción Español
Trust Boundary Violation
Trustworthy Java
Uncaught exception
Unchecked Return Value: Missing Check against Null
Unreleased Resource
Unsafe JNI
Unsafe Mobile Code
Unsafe Reflection
Using JCaptcha
Using the Java Cryptographic Extensions
Using the Java Secure Socket Extensions
XPATH Injection Java

Team

Coordination: Tasha CARL


Meta

  • Start: 12/2015
  • Last Update: 12/2015


Other Resources

N/A


Classifications

OWASP Java and JVM Project - Wiki Pages Review Operation 1 - 2015/2016



PROJECT INFO
What does this OWASP project offer you?
RELEASE(S) INFO
What releases are available for this project?
what is this project?
Name: OWASP Java Project WIPRO 1 - 2015/2016
Purpose: N/A
License: N/A
who is working on this project?
Project Leader(s):
how can you learn more?
Project Pamphlet: Not Yet Created
Project Presentation:
Mailing list: N/A
Project Roadmap: Not Yet Created
Key Contacts
current release
Not Yet Published
last reviewed release
Not Yet Reviewed


other releases