Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
Security Patterns 2012
Search
Mike Wiesner
November 08, 2012
Programming
57
0
Share
Embed
Copy iframe code
Copy JS code
Copy link
Start on current slide
Security Patterns 2012
Mike Wiesner
November 08, 2012
More Decks by Mike Wiesner
See All by Mike Wiesner
Transaktionen in Java
mikewiesner
0
97
Introduction to Spring Security 3/3.1
mikewiesner
0
140
Other Decks in Programming
See All in Programming
全PRの83%がAIレビューだけでマージできるようになった開発組織はその後どうなったか
athug
1
1.5k
仕様書を書く前にハーネスを作る - Agent Native開発は「探索を速く、判定を固く」
gotalab555
4
1.6k
使いながら育てる Claude Code — 開発フローの1コマンド化 × 繰り返し指摘の自動仕組み化
shiki_kakaku
0
1.7k
ルールを書いて終わらせないハーネスエンジニアリング
yug1224
4
1.9k
yield再入門 #phpcon
o0h
PRO
0
980
琵琶湖の水は止められてもNet--HTTPのリトライは止められない / You might be able to stop the water flow of Lake Biwa but you can't stop Net::HTTP retries
luccafort
PRO
0
610
数百円から始めるRuby電子工作
tarosay
0
140
プロポーザルを書いてもらう
pvcresin
0
290
AI時代、エンジニアはどう育つのか -未経験エンジニアの成長を間近で見て考えたこと-
thasu0123
0
220
AWS DevOps AgentのAzure接続機能を検証して見えた活用法/Use Cases Verified for the AWS DevOps Agent's Azure Connectivity Feature
masakiokuda
1
220
【やさしく解説 設計編・中級 #4】ルールの寿命と、システムの年輪
panda728
PRO
2
180
ドリフトを絶対に許さない(?)CDK運用 / CDK Ops with Zero Tolerance for Drifts (?)
akihisaikeda
1
180
Featured
See All Featured
Visual Storytelling: How to be a Superhuman Communicator
reverentgeek
2
610
Primal Persuasion: How to Engage the Brain for Learning That Lasts
tmiket
0
400
How to Align SEO within the Product Triangle To Get Buy-In & Support - #RIMC
aleyda
2
1.8k
Save Time (by Creating Custom Rails Generators)
garrettdimon
PRO
32
4.3k
Build The Right Thing And Hit Your Dates
maggiecrowley
39
3.4k
The Impact of AI in SEO - AI Overviews June 2024 Edition
aleyda
5
1.2k
Reflections from 52 weeks, 52 projects
jeffersonlam
356
21k
How to build a perfect <img>
jonoalderson
1
5.9k
Art, The Web, and Tiny UX
lynnandtonic
304
22k
Digital Ethics as a Driver of Design Innovation
axbom
PRO
1
360
Fight the Zombie Pattern Library - RWD Summit 2016
marcelosomers
234
17k
The Art of Delivering Value - GDevCon NA Keynote
reverentgeek
16
2.1k
Transcript
Security Patterns mehr als nur Authentifizierung und Autorisierung Mike Wiesner
[email protected]
None
Application Security?
Enterprise Java = Spring Spring + Security = Spring Security
Authentication Authorization
Fertig?
• Injection • Cross-Site Scripting (XSS) • Broken Authentication and
Session Management • Insecure Direct Object References • Cross-Site Request Forgery (CSRF) • Security Misconfiguration • Insecure Cryptographic Storage • Failure to Restrict URL Access • Insufficient Transport Layer Protection • Unvalidated Redirects and Forwards OWASP Top Ten
Security ist ein Prozess
select * from users where user = 'user' and password
= '' or '1' = '1' Login BBI Webserver Client Database ' or '1' = '1 user SQL Injection
XML Processing
fromFile newOrderXml download box downloadSecured boxSecured
Alle noch wach?
Demo Time!
Input Validation
JSR-303: Bean Validation public class Address { @NotNull @Length(max=30) private
String addressline1; @Length(max=30) private String addressline2; }
Trust Zones
None
OWASP Top Ten • Injection • Cross-Site Scripting (XSS) •
Broken Authentication and Session Management • Insecure Direct Object References • Cross-Site Request Forgery (CSRF) • Security Misconfiguration • Insecure Cryptographic Storage • Failure to Restrict URL Access • Insufficient Transport Layer Protection • Unvalidated Redirects and Forwards
Demo Time!
Security Misconfiguration • Eingesetzte Frameworks kennen • Eingesetze Frameworks dokumentieren
• Prozess bei Security Bugs in Frameworks • Frameworks “verstecken”
OWASP Top Ten • Injection • Cross-Site Scripting (XSS) •
Broken Authentication and Session Management • Insecure Direct Object References • Cross-Site Request Forgery (CSRF) • Security Misconfiguration • Insecure Cryptographic Storage • Failure to Restrict URL Access • Insufficient Transport Layer Protection • Unvalidated Redirects and Forwards
Fertig?
Encoding Problems Internet Tomcat Browser File- System ../ %C0%AE%C0%AE%C0%AF
Defense in Depth
Fazit • Application Security ist ein Prozess • Jeder Entwickler
muss die Grundlagen kennen • Darf nicht die Innovation stoppen • Frameworks können dabei helfen, • aber nicht alle Probleme lösen!
Mike Wiesner
[email protected]
http://bit.ly/SECPATTERN12