Discussion on Esapi use from Javaweb dangerous character filtration

Source: Internet
Author: User

In advance: Just talking about, I also used this component a little bit.

And to an important XX period (hopefully this article to meet the needs of the colleagues to help), a Web application for the first time to face the security requirements, AppScan Security test report is very refreshing, comprehensive content, hints suggest in place, and is noon Oh, of course some Chinese obviously Dog.

Before this application of the back-end architecture is relatively solid, so the important problem is near the front-end direction of the problem, some similar to the output filtering action does not put in place, need to introduce more mature code specifically to do these jobs, turned a Wu Yu Qing classmate "White hat talk about Web security" Recommended owasp Esapi, this thing is called Enterprise Security API, official website address: Https://www.owasp.org/index.php/Category:OWASP_Enterprise_ Security_api to his home page, as if to provide a lot of language branch version, I have a Java EE version, this thing is very powerful, directly to the Official Document feature list:

  1. The features in this release of ESAPI for Java EE include:
  2. ESAPI Core Components
  3. ESAPI Locator and interface classes.
  4. ESAPI security Control reference implementations for the following security controls:
  5. Authentication
  6. Identity
  7. Access Control
  8. Input Validation
  9. Output escaping
  10. Encryption
  11. Random Numbers
  12. Exception Handling
  13. Logging
  14. Intrusion Detection
  15. Security Configuration
  16. Esapi Web Application Firewall (WAF) component
  17. Fixes for specific issues. For more information, see "Enhancements and resolved issues".

This component uses not directly into the jar is OK, the initialization to read two configuration files esapi.properties and validation.properties, these two configuration files may not be found in the directory shown in the installation guide, but you unzip the search for the dist directory , should be able to find, put the two files into the SRC directory is ok.

What can be said, to code, I used a bit of defaultencoder in some of the encodeforxxx function, basically are getinstance () single-case way to get a sentence, there is nothing to say, we look at the document who will. What about this blog? Mainly want to say now the Chinese online search about Javaweb output filtering is mostly some people (in fact, a version) of their own code, not to say that his code is not good, the introduction of relatively mature through a certain use of component-level code is always relatively better, how to say, these things are security-related stuff, not to be belittled.

Discussion on Esapi use from Javaweb dangerous character filtration

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.