Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: J2EE Application Security Code Review |
|---|---|
| Date: | Sun, 30 Oct 2005 16:56:43 -0500 |
-dhs
On Oct 28, 2005, at 7:51 AM, Prashant Shirangare wrote:
Hi Yousef,
U can download findbug tool from below mentioned URL :
http://sourceforge.net/project/showfiles.php?group_id=96405
And more information about this tool is available on following URL :
http://findbugs.sourceforge.net/
Sample output of findbug is available on following URL:
http://findbugs.sourceforge.net/commons-modeler.html
Above tools will help u in detecting security issues in Java code ...
Regards Prashant
-----Original Message----- From: Yousef Syed [mailto:yousef.syed@gmail.com] Sent: Friday, October 28, 2005 3:33 PM To: Web Application Security Subject: J2EE Application Security Code Review
Hi, I've been tasked with performing a Code Review on for Security on a J2EE Application's code. Though I've taken part in numerous Code Reviews, I've never done one searching for Security issues.
Can someone please advise me on what I should be looking for? Where can I get further information on the procedure that should be followed? Are there any Standards/Best Practices for Securing J2EE applications?
Thanx, ys
-- Yousef Syed
*********************************************************
Disclaimer:
The contents of this E-mail (including the contents of the enclosure (s) or attachment(s) if any) are privileged and confidential material of MBT and should not be disclosed to, used by or copied in any manner by anyone other than the intended addressee(s). In case you are not the desired addressee, you should delete this message and/or re-direct it to the sender. The views expressed in this E-mail message (including the enclosure(s) or attachment(s) if any) are those of the individual sender, except where the sender expressly, and with authority, states them to be the views of MBT.
This e-mail message including attachment/(s), if any, is believed to be free of any virus. However, it is the responsibility of the recipient to ensure that it is virus free and MBT is not responsible for any loss or damage arising in any way from its use
********************************************************
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: Smells like a phish, is a fish?, Devdas Bhagat |
|---|---|
| Next by Date: | RE: Smells like a phish, is a fish?, Lyal Collins |
| Previous by Thread: | RE: J2EE Application Security Code Review, Prashant Shirangare |
| Next by Thread: | RE: J2EE Application Security Code Review, Evans, Arian |
| Indexes: | [Date] [Thread] [Top] [All Lists] |