Security Code Review- Identifying Web Vulnerabilities

Contributed by Kiran Maraju. Revived from the old site.

This paper gives an introduction of security code review inspections, and provides details about web application security vulnerabilities identification in the source code. This paper gives the details of the inspections to perform on the Java/J2EE source code. This paper explains the process of identifying vulnerable code and remediation details. This paper illustrates the specific locations of code flows to be checked to identify web application vulnerabilities.

This document is in PDF format. To view it click here.

