Secure Coding in Java (2020)

Secure Coding in Java (2020)

1hAdvanced2020-11-03

Authors

Frank P Moley III

Frank P Moley III

Senior Principal Engineer at Catch&Release

Course details

The enduring popularity of Java makes it a target for bad actors. And its prevalence in internal enterprise applications—which are vulnerable to attacks from employees with insider knowledge—renders secure coding practices even more critical. In this course, instructor Frank Moley helps advanced Java developers kick-start their secure coding journey, providing a high-level look at common attacks against Java applications, as well as how to prevent and defend against those threats. Frank discusses how to prevent SQL injection attacks, identify places where sensitive data is stored and avoid exposing it to the outside world, write code that protects the integrity of the system, and more. Along the way, he provides challenges that allow you to put your new skills to the test.

Skills covered

Software Development SecurityJavaOracleCybersecurityProgramming LanguagesSoftware DevelopmentOne-Off

Concepts

Introduction

  • Keeping secure in Java
  • What you should know

Preventing Injection Attacks

  • Injection attacks
  • Prevent SQL injection
  • Other injection attacks
  • Challenge - Refactor Java code susceptible to injection attacks
  • Solution - Refactor Java code susceptible to injection attacks

Protecting Sensitive Data

  • Sensitive data leak
  • Log message leaks
  • Exception leaks
  • Challenge - Prevent sensitive data leaks
  • Solution - Prevent sensitive data leaks

Resolving Access Vulnerabilities

  • Class and package accessibility
  • Mutability
  • Extensibility

Additional Vulnerability Remediation

  • Build vulnerabilities
  • Input validation
  • Serialization
40,000 Toman