Download presentation
Presentation is loading. Please wait.
Published byAvice Eleanore Harmon Modified over 8 years ago
1
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the OWASP License. The OWASP Foundation OWASP http://www.owasp.org OWASP LAPSE+ Project Bruno Motta Rego bmr@attom.com.br June 2011
2
OWASP 2 Agenda Introduction Vulnerabilities Detected Goals Hands On Case Challenges
3
OWASP 3 Introduction LAPSE+ is a static analysis of code Eclipse plugin for detecting vulnerabilities of untrusted data injection in Java EE Applications. LAPSE+ is inspired by existing lightweight security auditing tools such as FlawFinder. Developed by Group of Stanford University. GPL Software.
4
OWASP 4 Vulnerabilities Detected URL Tampering Cookie Poisoning Parameter Tampering Header Manipulation Cross-site Scripting (XSS) HTTP Response Splitting Injections (SQL, Command, XPath, XML, LDAP) Path Traversal
5
OWASP 5 Goals Practical Understanding Challenges
6
OWASP 6 Hands On
7
OWASP 7 LAPSE+ Installation Eclipse Helios http://www.eclipse.org/downloads/ http://www.eclipse.org/downloads/ LAPSE+ 2.8.1 plugin for Eclipse Helios. http://evalues.es/downloads/owasp/LapsePlus_2.8.1.jar http://evalues.es/downloads/owasp/LapsePlus_2.8.1.jar
8
OWASP 8 LAPSE+ Configuration Drag and Drop Copy it in the plugins folder of our Eclipse Helios
9
OWASP 9 LAPSE+ Steps Vulnerability Source Vulnerability Sink Provenance Tracker
10
OWASP 10 Challenges Requirements Eclipse Helios Java 1.6 or higher Support Senior Management Developers approve and use LAPSE+ Project Troughput down
11
OWASP 11 Case
12
OWASP 12 Software Security Challenge Total Cost of Development
13
OWASP 13 Questions and Answers
Similar presentations
© 2025 SlidePlayer.com. Inc.
All rights reserved.