11.07.2015 Views

EC-Council Certified Secure Programmer

EC-Council Certified Secure Programmer

EC-Council Certified Secure Programmer

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

o Code for GSS Client• Java Server Page (JSP)o Problem of Untrusted User Inputo JSP Security Issues: Sensitive Data in GET Requests and Cookieso JSP Best Practices• Security with Untrusted User Input• Cross Site Scripting• Overcoming Cross Site Scripting Problem• Authentication in Java• Permissions in Java• How to create new types of permissions?• Security Policy• Specifying an additional Policy File at runtime• Policy Toolo Policy Tool: Creating a new Policy File• Best practices for developing secure Java CodePage 15Module 07: <strong>Secure</strong> Java Script and VB Script Programming• Script: Introduction• JavaScript Vulnerability• Cross-Site Scripting (XSS)• Cross-Site Scripting Attacks• Avoiding XSS• JavaScript Hijacking• Defending Against JavaScript Hijacking• Declining Malicious Requests• Prevent Direct Execution of the JavaScript Response• Malicious Script Embedded in Client Web Requestshttp://www.eccouncil.org<strong>EC</strong>-<strong>Council</strong>

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!