Chia sẻ kiến thức IT ứng dụng: AI, Backend, Frontend, Full Stack, DevOps & Cloud, and More.

Showing posts with label App Security. Show all posts
Showing posts with label App Security. Show all posts

Sunday, July 5, 2020

SSO java-servlet-application-with-keycloak

There are some concepts relating to SSO - single sign on in software applications.

What is OpenID?

OpenID allows you to use an existing account to sign in to multiple websites, without needing to create new passwords.
You may choose to associate information with your OpenID that can be shared with the websites you visit, such as a name or email address. With OpenID, you control how much of that information is shared with the websites you visit.
With OpenID, your password is only given to your identity provider, and that provider then confirms your identity to the websites you visit.  Other than your provider, no website ever sees your password, so you don’t need to worry about an unscrupulous or insecure website compromising your identity.
So when talking about OpenID it means we are talking about authentication topics.

Saturday, July 4, 2020

Spring Security Overview

Spring Security is a powerful and highly customizable authentication and access-control framework. It is the de-facto standard for securing Spring-based applications.
Spring Security is a framework that focuses on providing both authentication and authorization to Java applications. Like all Spring projects, the real power of Spring Security is found in how easily it can be extended to meet custom requirements

Tuesday, April 5, 2016

SQL Injection

1> SQL injection (SQLi) refers to an injection attack wherein an attacker can execute malicious SQL statements (also commonly referred to as a malicious payload) that control a web application’s database server (also commonly referred to as a Relational Database Management System – RDBMS). (http://www.acunetix.com/websitesecurity/sql-injection/)
  • An SQL Injection can destroy your database.
  • SQL injection can provide an attacker with unauthorized access to sensitive data including, customer data, personally identifiable information (PII), trade secrets, intellectual property and other sensitive information.
  • SQL Injection Based on 1=1 is Always True

PHỔ BIẾN

CHUYÊN MỤC

TỔNG LƯỢT XEM