Network World
Friday, September 5, 2008
DNSstuff.com
Get information about your IP
IP Information
50+ On-demand DNS and network tools

Community: Software

Navigation

RE: Standards suggested for writing secure Java

Don't bother with these guys

0

They mention the dangers of SQL injection, but not those of command line injection via Runtime.exec. They also don't discuss how to structure/process dynamic requests to prevent injection. They mention JSP's but not the dangers of the JSP compiler, or the benefits of JSP precompilation and removal of the JSP compiler. They don't talk about the principle of protocol transformation. They mention JAAS but not PAM's or LDAP. No talk of SSO and the impact of global sessions. No mention of how to use hardware routers with NAT and VPN. They mention exceptions, but nothing about modifying the standard error page not to display the exception call stack back to the caller. No mention of the hazards of JNI.

GAH!!!

Seriously. Don't bother with these guys until/unless they progress beyond the n00b stage.

2 cents

0

They are talking about programming practices they refer to as "industry standards" they will claim when used reduce release of vulnerable code.

How to solve infra-structure issues or how to work out the security issues of authentication and authorization is something learned in college.

Having said that, I agree with your advice not to bother with these guys [unless you need stuffing for your resumé].

Sounds like they are trying to carve a market for themselves; maybe the sponsors of this group will give preference to programmers who go through the program.

Comment viewing options

Select your preferred way to display the comments and click "Save settings" to activate your changes.

Latest software headlines from Network World:

File storage and viewing apps for iPhone

How to Ruin a Great Application

Microsoft's lab cooks up photo collage program

Office 2008 survival guide

Hear 1.0

  1   2   3   4   5   6   7   8   9  10  next 

Advertisement: