 |
Ajax for Java Developers
Mastering the JSTL (Java Standard Tag Library) training
Authoring JSP Tag Libraries training
Jakarta Struts training
Introduction to JSF (JavaServer Faces)
Building Data-Driven JSP Web Sites with Dreamweaver training
Introduction to the Spring Framework training
Introduction to Hibernate training
Introduction to JMS (Java Message Service) training
Live Online Training

Please contact us
for GSA pricing.

Contract #
GS-35F-0307T
Complimentary Servlets & JSP Training Seminar
Organizations in the Atlanta, Georgia area are encouraged
to contact Accelebrate® about having a complimentary, one-hour Java servlets
/ JSP training seminar delivered for their developers. Contact
us today for more information.

Recent Training Venues
Accelebrate has recently trained for clients in the following cities:
- Huntsville, Alabama
- Montgomery / Birmingham, Alabama
- Anchorage, Alaska
- Calgary, Alberta
- Phoenix, Arizona
- Fayetteville / Little Rock, Arkansas
- Oakland / San Jose / San Francisco, California
- Oceanside / San Diego, California
- Pasadena / Orange County / Los Angeles, California
- San Bernardino / Riverside, California
- Boulder / Colorado Springs / Denver, Colorado
- Washington, DC
- Wilmington, Delaware
- Manchester / London, England
- DeLand / Orlando, Florida
- Fort Lauderdale / Miami, Florida
- Gainesville / Jacksonville, Florida
- Saint Petersburg / Tampa, Florida
- Titusville & Melbourne, Florida
- Alpharetta & Atlanta, Georgia
- Augusta & Savannah, Georgia
- Macon & Columbus, Georgia
- Bloomington, Illinois
- Chicago, Illinois
- Indianapolis, Indiana
- Cedar Rapids / Des Moines, Iowa
- Dublin, Ireland
- Kingston, Jamaica
- Wichita, Kansas
- Paducah / Lexington / Louisville, Kentucky
- Baton Rouge, Louisiana
- Valletta, Malta
- Hagerstown & Frederick, Maryland
- Greenbelt / Silver Spring / Baltimore, Maryland
- Boston / Cambridge, Massachusetts
- Hartford, Connecticut / Springfield, Massachusetts
- Taunton, Massachusetts / Providence, Rhode Island
- Ann Arbor / Farmington Hills / Detroit, Michigan
- Grand Rapids, Michigan
- Lansing, Michigan
- Saginaw / Flint / Bay City / Midland, Michigan
- Saint Paul / Minneapolis, Minnesota
- Jackson, Mississippi
- Gulfport / Biloxi, Mississippi
- Whiteman Air Force Base / Kansas City, Missouri
- Reno and Las Vegas, Nevada
- Santa Fe / Albuquerque, New Mexico
- Newark, New Jersey
- Princeton, New Jersey & Philadelphia, Pennsylvania
- White Plains / New York City, New York
- Charlotte, North Carolina
- Durham / Raleigh, North Carolina
- Bowling Green / Toledo, Ohio
- Cincinnati, Ohio
- Cleveland & Columbus, Ohio
- Tulsa / Oklahoma City, Oklahoma
- Toronto, Ontario
- Portland, Oregon
- Pittsburgh, Pennsylvania
- Providence, Rhode Island
- Edinburgh / Glasgow, Scotland
- Columbia & Charleston, South Carolina
- Memphis / Jackson / Nashville, Tennessee
- College Station and Houston, Texas
- El Paso, Texas / Ciudad Juarez, Mexico
- San Antonio / Austin, Texas
- Wichita Falls & Dallas, Texas
- Ogden / Salt Lake City, Utah
- Burlington, Vermont
- Fairfax / Dulles / McLean / Herndon / Reston, Virginia
- Richmond / Alexandria / Arlington, Virginia
- Virginia Beach / Norfolk, Virginia
- Tacoma / Seattle, Washington
- Madison / Milwaukee, Wisconsin
|
 |
 |
Java Web Application Security Training: Securing Java Web Applications
|
Course Number: 293
Duration: 3 days
view class outline
Java Web Application Security Training Overview
This advanced course shows experienced developers of Java web applications how to secure those applications and to apply best practices with regard to secure enterprise coding. Authentication, authorization, and input validation are major themes, and students get good exposure to basic Java cryptography for specific development scenarios, as well as thorough discussions of HTTPS configuration and certificate management, error handling, logging, and auditing.
Location and Pricing
Most Accelebrate courses are taught on-site at our clients' locations worldwide for groups of 3 or more attendees and are customized to their specific needs. Please visit our client list to see organizations for whom we have recently delivered training. To receive a customized proposal and price quote, please contact us.
In addition, some courses are available as live, online classes for individuals. To see a schedule of online courses, please visit http://www.accelebrate.com/online_training/java.htm.
Java Web Application Security Training Prerequisites
- Java programming experience is essential.
- Servlets programming experience is required.
- JSP page-authoring experience is recommended but not required.
Hands-on/Lecture Ratio
This class is 70% hands-on, 30% lecture, with the longest lecture segments lasting for 20 minutes.
Java Web Application Security Training Materials
All Java web application security training attendees receive comprehensive courseware covering all topics listed.
Software Needed on Each Student PC
- JDK 5.0 or later
- Eclipse WTP 2.0 or later
- Additional lab files that Accelebrate will provide – please contact us if you need a detailed setup guide.
Java Web Application Security Training Objectives
All attendees will learn how to:
- Secure new and existing Java web applications.
- Define security constraints and login configurations that instruct the web container to enforce authentication and authorization policies.
- Validate user input aggressively, for general application health and specifically to foil injection and XSS attacks.
- Configure a server and/or application to use one-way or two-way HTTPS.
- Apply application-level cryptography where necessary.
- Secure log files and establish audit trails for especially sensitive information or actions.
|
Java Web Application Security Training Outline
- Secure Web Applications
- Defense in Depth
- Server, Network, and Browser Vulnerabilities
- HTTP and HTTPS
- GET vs. POST
- Secure Servers and Containers
- HTML Forms
- Server Security Policies
- Container Authentication and Authorization
- Privacy Under /WEB-INF
- SOA and Web Services
- The OWASP Top 10
- Authentication and Authorization
- HTTP BASIC and DIGEST Authentication Schemes
- Declaring Security Constraints
- User Accounts
- Replay Attacks
- Authorization Over URL Patterns
- Roles in Servlets
- Roles in JSF and Web Frameworks
- FORM Authentication
- Login Form Design
- EJB Authorization
- Programmatic Security
- JSF Issues
- Secure Application Design
- Single Points of Enforcement
- Parameter Tampering
- Forceful Browsing
- Cross-Site Request Forgery
- Injection Attacks
- Protections in JDBC and JPA
- Cross-Site Scripting
- Validation vs. Output Escaping
- Client-Side State
- Session Management
- Cookies
- Validating User Input
- Levels of Validation
- Regular Expressions
- The Apache Commons Validator
- JSF Validation
- HTTPS and Certificates
- Digital Cryptography
- Encryption
- Hashing
- Signature
- Keystores
- keytool
- Why Keys Aren't Enough
- X.509 Certificates
- Certificate Authorities
- Obtaining a Signed Certificate
- Configuring HTTPS
- Client-Side Certificates
- PKCS #12 and Trust Stores
- Cryptography Primer
- The Java Cryptography Architecture
- The Signature Class
- The SignedObject Class
- The MessageDigest Class
- The Java Cryptography Extensions
- The SecretKey and KeyGenerator Types
- The Cipher Class
- Choosing Algorithms and Key Sizes
- Dangerous Practices
- Secure Random Number Generation
- Error Handling, Auditing, and Logging
- Secure Development Cycle
- Unhandled Errors as Windows of Opportunity
- Failing to a Secure Mode
- Information Leakage
- Appropriate Content for Logs
- Securing Log Files
- Auditing
- Strategies: Filters, Interceptors, and Command Chains
- Penetration Testing
- Back Doors
- Conclusion
|
| |
JBoss® and Hibernate® are registered trademarks of Red Hat, Inc. Accelebrate, Inc. has no affiliation with Red Hat, Inc. and no courses offered by Accelebrate, Inc. are endorsed by Red Hat, Inc. in any way.
|
 |
Accelebrate®
Comes to You! |
 |
Accelebrate's courses are taught exclusively on-site at your location for groups of 3 or more attendees, anywhere worldwide.
Don't settle for a "one size fits all" public class! Have Accelebrate come to your site and deliver exactly the training you want, for less than the cost of a public class.
For pricing and to learn more, please call us at +1 877 849 1850, fill out our information request form, or email us at info@accelebrate.com today.

|
 |
| |
Accelebrate accomplished the goal of providing a thorough introduction to Java,
JSP, JavaBeans and JSTL. Following this training, we will be able to hit the
ground running!  |
| |
—Jeff Paar
Jewelry Television
Knoxville, Tennessee |
|
 |