Hi, I'm new to JSP/Servlet, or can say web application development. So I am very much interested (or needed) to know about the security issue, password encryption, how to prevent some one else from accessing my database from JSP/Servlet... and so on.

I run a search in google, EE and the result just make my head grows bigger. All those results of hash your password, usage of MD5, DES just don't make sense for my fragile little mind.

So what I need is maybe some introduction to some important security issue and some links that can be a help to me.

Siva Prasanna KumarConnect With a Mentor Principal Solutions ArchitectCommented:

refer the above source

and to secure your password ans user name of the database you need to use some kind of effective encryption technique.

java provides all many of the standard encryption implementations.

check here to know how to use them.

InNoCenT_Ch1ldAuthor Commented:
j2ee... hmm, can they be use if I run my web apps on tomcat? or other web server?
InNoCenT_Ch1ldAuthor Commented:
btw, does each different type of webserver provide their own type of security?
Siva Prasanna KumarPrincipal Solutions ArchitectCommented:
>>webserver provide their own type of security

yes but all the webservers must provide the standard J2EE security specified.

and about Tomcat, Tomcat is a java servlet engine which are part of J2ee(servlets).

InNoCenT_Ch1ldAuthor Commented:
well, I'll let this question open for another day to close it.

Tks for your swift respond. ;-)
WelkinMazeConnect With a Mentor Commented:

For some simplified information as an overview you  may look at

Also as I said before if you using https then you have a secure connection between your client and server, so the username and password are not visible for everyone that may be hacking in the middle.
