Spring Boot application demonstrating secure database access over HTTPS, defending against phishing credential harvesting and SQL injection attacks.
MSCS-535 Secure Software Development
University of the Cumberlands
A phishing email impersonating an IT department harvests employee login credentials. The web application is also vulnerable to SQL injection. This implementation addresses both attack vectors simultaneously.
- HTTPS enforcement via KeyStore and SSL certificate
- Parameterized queries blocking SQL injection at the repository layer
- BCrypt hashing ensuring plaintext credentials are never stored
- Generic failure responses preventing information leakage on failed login
- Spring Security filter chain blocking unauthenticated requests
- SecureAccessApp.java - Spring Boot entry point
- Employee.java - Entity mapping to employees database table
- EmployeeRepository.java - Parameterized query blocking SQL injection
- SystemSecurityConfig.java - HTTPS enforcement and BCrypt configuration
- SystemController.java - Login and dashboard endpoints
- application.properties - HTTPS and database configuration
- pom.xml - Maven dependencies
Run the following command to generate the SSL certificate before starting the application:
keytool -genkeypair -alias secureaccess -keyalg RSA -keysize 2048 \
-storetype PKCS12 -keystore keystore.p12 -validity 365- Richardson, T., & Thies, C. N. (2012). Secure software design. Jones & Bartlett Learning.
- VMware, Inc. (2023). Spring Boot reference documentation. Spring.
- VMware, Inc. (2023). Spring Security reference documentation. Spring.
- VMware, Inc. (2023). Spring Data JPA reference documentation. Spring.