This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org
Difference between revisions of "OWASP Java Project WIPRO 1 2015"
From OWASP
m (→Classifications) |
m |
||
| Line 14: | Line 14: | ||
| valign="top" style="border-right: 1px dotted gray;padding-right:25px;width:100%" | | | valign="top" style="border-right: 1px dotted gray;padding-right:25px;width:100%" | | ||
| − | + | 91 Pages in category "OWASP Java Project" to be reviewed. | |
| + | {| class="wikitable" | ||
| + | ! Page | ||
| + | ! Review | ||
| + | ! Decision | ||
| + | ! Comments | ||
| + | |- | ||
| + | |[[Bytecode obfuscation]] | ||
| + | | | ||
| + | | | ||
| + | | | ||
| + | |- | ||
| + | |[[Captchas in Java ]] | ||
| + | | | ||
| + | | | ||
| + | | | ||
| + | |- | ||
| + | |[[Clickjacking Protection for Java EE]] | ||
| + | | | ||
| + | | | ||
| + | | | ||
| + | |- | ||
| + | |[[Command injection in Java]] | ||
| + | | | ||
| + | | | ||
| + | | | ||
| + | |- | ||
| + | |[[Comparing classes by name ]] | ||
| + | | | ||
| + | | | ||
| + | | | ||
| + | |- | ||
| + | |[[Complejidad Y Longitud De Las Contraseñas ]] | ||
| + | | | ||
| + | | | ||
| + | | | ||
| + | |- | ||
| + | |[[Content Security Policy ]] | ||
| + | | | ||
| + | | | ||
| + | | | ||
| + | |- | ||
| + | |[[CORS OriginHeaderScrutiny]] | ||
| + | | | ||
| + | | | ||
| + | | | ||
| + | |- | ||
| + | |[[CORS RequestPreflighScrutiny]] | ||
| + | | | ||
| + | | | ||
| + | | | ||
| + | |- | ||
| + | |[[Cross-site Scripting (XSS) ]] | ||
| + | | | ||
| + | | | ||
| + | | | ||
| + | |- | ||
| + | |[[Declarative Access Control in Java]] | ||
| + | | | ||
| + | | | ||
| + | | | ||
| + | |- | ||
| + | |[[Decompiling Java bytecode]] | ||
| + | | | ||
| + | | | ||
| + | | | ||
| + | |- | ||
| + | |[[Deserialization of untrusted data]] | ||
| + | | | ||
| + | | | ||
| + | | | ||
| + | |- | ||
| + | |[[Detect profiling phase into web application]] | ||
| + | | | ||
| + | | | ||
| + | | | ||
| + | |- | ||
| + | |[[Digital Signature Implementation in Java]] | ||
| + | | | ||
| + | | | ||
| + | | | ||
| + | |- | ||
| + | |[[Exception handling techniques ]] | ||
| + | | | ||
| + | | | ||
| + | | | ||
| + | |- | ||
| + | |[[Failure to follow guideline/specification ]] | ||
| + | | | ||
| + | | | ||
| + | | | ||
| + | |- | ||
| + | |[[Hacking Java Clients ]] | ||
| + | | | ||
| + | | | ||
| + | | | ||
| + | |- | ||
| + | |[[Hashing Java]] | ||
| + | | | ||
| + | | | ||
| + | | | ||
| + | |- | ||
| + | |[[Hibernate]] | ||
| + | | | ||
| + | | | ||
| + | | | ||
| + | |- | ||
| + | |[[Hibernate-Guidelines ]] | ||
| + | | | ||
| + | | | ||
| + | | | ||
| + | |- | ||
| + | |[[How to add validation logic to HttpServletRequest]] | ||
| + | | | ||
| + | | | ||
| + | | | ||
| + | |- | ||
| + | |[[How to encrypt a properties file ]] | ||
| + | | | ||
| + | | | ||
| + | | | ||
| + | |- | ||
| + | |[[Implementacion De Firmas Digitales en Java]] | ||
| + | | | ||
| + | | | ||
| + | | | ||
| + | |- | ||
| + | |[[Improper Data Validation]] | ||
| + | | | ||
| + | | | ||
| + | | | ||
| + | |- | ||
| + | |[[Improper temp file opening ]] | ||
| + | | | ||
| + | | | ||
| + | | | ||
| + | |- | ||
| + | |[[Information Leakage]] | ||
| + | | | ||
| + | | | ||
| + | | | ||
| + | |- | ||
| + | |[[Insecure Randomness]] | ||
| + | | | ||
| + | | | ||
| + | | | ||
| + | |- | ||
| + | |[[Insecure Transport]] | ||
| + | | | ||
| + | | | ||
| + | | | ||
| + | |- | ||
| + | |[[Insufficient Session-ID Length]] | ||
| + | | | ||
| + | | | ||
| + | | | ||
| + | |- | ||
| + | |[[Invoking untrusted mobile code]] | ||
| + | | | ||
| + | | | ||
| + | | | ||
| + | |- | ||
| + | |[[Inyección De Comandos En Java ]] | ||
| + | | | ||
| + | | | ||
| + | | | ||
| + | |- | ||
| + | |[[J2EE Misconfiguration: Unsafe Bean Declaration]] | ||
| + | | | ||
| + | | | ||
| + | | | ||
| + | |- | ||
| + | |[[J2EE third party libraries insecurity]] | ||
| + | | | ||
| + | | | ||
| + | | | ||
| + | |- | ||
| + | |[[JAAS Timed Login Module ]] | ||
| + | | | ||
| + | | | ||
| + | | | ||
| + | |- | ||
| + | |[[JAAS Tomcat Login Module]] | ||
| + | | | ||
| + | | | ||
| + | | | ||
| + | |- | ||
| + | |[[Java Project Article Wishlist ]] | ||
| + | | | ||
| + | | | ||
| + | | | ||
| + | |- | ||
| + | |[[Java Security Frameworks]] | ||
| + | | | ||
| + | | | ||
| + | | | ||
| + | |- | ||
| + | |[[Java Security Resources ]] | ||
| + | | | ||
| + | | | ||
| + | | | ||
| + | |- | ||
| + | |[[Java Server Faces ]] | ||
| + | | | ||
| + | | | ||
| + | | | ||
| + | |- | ||
| + | |[[JSP errorPage]] | ||
| + | | | ||
| + | | | ||
| + | | | ||
| + | |- | ||
| + | |[[JSP JSTL ]] | ||
| + | | | ||
| + | | | ||
| + | | | ||
| + | |- | ||
| + | |[[Leftover Debug Code]] | ||
| + | | | ||
| + | | | ||
| + | | | ||
| + | |- | ||
| + | |[[Log Forging ]] | ||
| + | | | ||
| + | | | ||
| + | | | ||
| + | |- | ||
| + | |[[Logout]] | ||
| + | | | ||
| + | | | ||
| + | | | ||
| + | |- | ||
| + | |[[Member Field Race Condition]] | ||
| + | | | ||
| + | | | ||
| + | | | ||
| + | |- | ||
| + | |[[Missing Error Handling]] | ||
| + | | | ||
| + | | | ||
| + | | | ||
| + | |- | ||
| + | |[[Mobile Java Security ]] | ||
| + | | | ||
| + | | | ||
| + | | | ||
| + | |- | ||
| + | |[[Null Dereference]] | ||
| + | | | ||
| + | | | ||
| + | | | ||
| + | |- | ||
| + | |[[Object Model Violation: Just One of equals() and hashCode() Defined]] | ||
| + | | | ||
| + | | | ||
| + | | | ||
| + | |- | ||
| + | |[[Often Misused: Authentication ]] | ||
| + | | | ||
| + | | | ||
| + | | | ||
| + | |- | ||
| + | |[[Overly-Broad Catch Block]] | ||
| + | | | ||
| + | | | ||
| + | | | ||
| + | |- | ||
| + | |[[Overly-Broad Throws Declaration]] | ||
| + | | | ||
| + | | | ||
| + | | | ||
| + | |- | ||
| + | |[[OWASP CSRFGuard Project/es ]] | ||
| + | | | ||
| + | | | ||
| + | | | ||
| + | |- | ||
| + | |[[OWASP Java Table of Contents]] | ||
| + | | | ||
| + | | | ||
| + | | | ||
| + | |- | ||
| + | |[[Parameter Validation Filter]] | ||
| + | | | ||
| + | | | ||
| + | | | ||
| + | |- | ||
| + | |[[Password length & complexity]] | ||
| + | | | ||
| + | | | ||
| + | | | ||
| + | |- | ||
| + | |[[Password Management: Hardcoded Password]] | ||
| + | | | ||
| + | | | ||
| + | | | ||
| + | |- | ||
| + | |[[Password Management: Weak Cryptography ]] | ||
| + | | | ||
| + | | | ||
| + | | | ||
| + | |- | ||
| + | |[[Password Plaintext Storage ]] | ||
| + | | | ||
| + | | | ||
| + | | | ||
| + | |- | ||
| + | |[[PDF Attack Filter for Java EE ]] | ||
| + | | | ||
| + | | | ||
| + | | | ||
| + | |- | ||
| + | |[[Poor Logging Practice]] | ||
| + | | | ||
| + | | | ||
| + | | | ||
| + | |- | ||
| + | |[[Preventing LDAP Injection in Java]] | ||
| + | | | ||
| + | | | ||
| + | | | ||
| + | |- | ||
| + | |[[Preventing SQL Injection in Java ]] | ||
| + | | | ||
| + | | | ||
| + | | | ||
| + | |- | ||
| + | |[[Process Control]] | ||
| + | | | ||
| + | | | ||
| + | | | ||
| + | |- | ||
| + | |[[Protecting code archives with digital signatures]] | ||
| + | | | ||
| + | | | ||
| + | | | ||
| + | |- | ||
| + | |[[Reflection attack in an auth protocol]] | ||
| + | | | ||
| + | | | ||
| + | | | ||
| + | |- | ||
| + | |[[Return Inside Finally Block]] | ||
| + | | | ||
| + | | | ||
| + | | | ||
| + | |- | ||
| + | |[[Securing tomcat]] | ||
| + | | | ||
| + | | | ||
| + | | | ||
| + | |- | ||
| + | |[[Servlet spec - web.xml]] | ||
| + | | | ||
| + | | | ||
| + | | | ||
| + | |- | ||
| + | |[[Session Fixation]] | ||
| + | | | ||
| + | | | ||
| + | | | ||
| + | |- | ||
| + | |[[Session Timeout]] | ||
| + | | | ||
| + | | | ||
| + | | | ||
| + | |- | ||
| + | |[[Signing jar files with jarsigner ]] | ||
| + | | | ||
| + | | | ||
| + | | | ||
| + | |- | ||
| + | |[[State synchronization error]] | ||
| + | | | ||
| + | | | ||
| + | | | ||
| + | |- | ||
| + | |[[Struts]] | ||
| + | | | ||
| + | | | ||
| + | | | ||
| + | |- | ||
| + | |[[Struts Validation in an ActionForm]] | ||
| + | | | ||
| + | | | ||
| + | | | ||
| + | |- | ||
| + | |[[Struts Validation in validator.xml using an ActionForm]] | ||
| + | | | ||
| + | | | ||
| + | | | ||
| + | |- | ||
| + | |[[Struts XSLT Viewer]] | ||
| + | | | ||
| + | | | ||
| + | | | ||
| + | |- | ||
| + | |[[Traducción Español]] | ||
| + | | | ||
| + | | | ||
| + | | | ||
| + | |- | ||
| + | |[[Trust Boundary Violation]] | ||
| + | | | ||
| + | | | ||
| + | | | ||
| + | |- | ||
| + | |[[Trustworthy Java]] | ||
| + | | | ||
| + | | | ||
| + | | | ||
| + | |- | ||
| + | |[[Uncaught exception]] | ||
| + | | | ||
| + | | | ||
| + | | | ||
| + | |- | ||
| + | |[[Unchecked Return Value: Missing Check against Null ]] | ||
| + | | | ||
| + | | | ||
| + | | | ||
| + | |- | ||
| + | |[[Unreleased Resource]] | ||
| + | | | ||
| + | | | ||
| + | | | ||
| + | |- | ||
| + | |[[Unsafe JNI]] | ||
| + | | | ||
| + | | | ||
| + | | | ||
| + | |- | ||
| + | |[[Unsafe Mobile Code]] | ||
| + | | | ||
| + | | | ||
| + | | | ||
| + | |- | ||
| + | |[[Unsafe Reflection ]] | ||
| + | | | ||
| + | | | ||
| + | | | ||
| + | |- | ||
| + | |[[Using JCaptcha ]] | ||
| + | | | ||
| + | | | ||
| + | | | ||
| + | |- | ||
| + | |[[Using the Java Cryptographic Extensions]] | ||
| + | | | ||
| + | | | ||
| + | | | ||
| + | |- | ||
| + | |[[Using the Java Secure Socket Extensions]] | ||
| + | | | ||
| + | | | ||
| + | | | ||
| + | |- | ||
| + | |[[XPATH Injection Java ]] | ||
| + | | | ||
| + | | | ||
| + | | | ||
| + | |} | ||
| valign="top" style="padding-left:25px;min-width:200px;border-right: 1px dotted gray;padding-right:25px;" | | | valign="top" style="padding-left:25px;min-width:200px;border-right: 1px dotted gray;padding-right:25px;" | | ||
Revision as of 08:55, 14 December 2015
Wiki Pages Review Operation - 2015/2016
OWASP Java and JVM Project - Wiki Pages Review Operation 1 - 2015/2016
| PROJECT INFO What does this OWASP project offer you? |
RELEASE(S) INFO What releases are available for this project? | |||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
| |||||||||||||||||||||||||||||||||||
