{"id":1472,"date":"2013-08-12T23:44:34","date_gmt":"2013-08-13T02:44:34","guid":{"rendered":"https:\/\/devkico.itexto.com.br\/?p=1472"},"modified":"2013-08-12T23:48:18","modified_gmt":"2013-08-13T02:48:18","slug":"melhorando-seguranca-de-scripts-na-jvm-voces-security-manager","status":"publish","type":"post","link":"https:\/\/devkico.itexto.com.br\/?p=1472","title":{"rendered":"Melhorando a seguran\u00e7a de scripts na JVM: com voc\u00eas o Security Manager!"},"content":{"rendered":"<p><a style=\"font-family: 'Helvetica Neue', Helvetica, Arial, sans-serif; font-size: 13px; font-style: normal; color: #3a3a3a;\" href=\"http:\/\/www.youtube.com\/watch?v=8egPIoqsuLI\"><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-1473 alignleft\" alt=\"securityManager\" src=\"https:\/\/devkico.itexto.com.br\/wp-content\/uploads\/2013\/08\/securityManager.jpg\" width=\"300\" height=\"169\" \/><\/a>O Security Manager \u00e9 a piscina do javeiro: aquele recurso que diversas plataformas computacionais sonham possuir e muitos de n\u00f3s simplesmente ignoramos.<\/p>\n<p>Neste v\u00eddeo irei mostrar bem por alto o que v\u00eam a ser este recurso e como voc\u00ea pode us\u00e1-lo para executar seus scripts em um ambiente isolado, impedindo assim diversas amea\u00e7as que vimos anteriormente, como por exemplo acesso indevido a arquivos, rede, finaliza\u00e7\u00e3o da JVM, etc.<\/p>\n<p>O v\u00eddeo ir\u00e1 mostrar por alto este recurso, no entanto voc\u00ea pode se aprofundar no assunto usando os links da refer\u00eancia a seguir.<\/p>\n<h2>Refer\u00eancias<\/h2>\n<p>No v\u00eddeo usamos uma implementa\u00e7\u00e3o customizada do Security Manager, no entanto, por padr\u00e3o a JVM j\u00e1 v\u00eam com uma excelente implementa\u00e7\u00e3o que nos permite trabalhar apenas alterando arquivos de configura\u00e7\u00e3o.<\/p>\n<p>Sobre a arquitetura de seguran\u00e7a do Java:\u00a0<a href=\"http:\/\/docs.oracle.com\/javase\/7\/docs\/technotes\/guides\/security\/overview\/jsoverview.html\">http:\/\/docs.oracle.com\/javase\/7\/docs\/technotes\/guides\/security\/overview\/jsoverview.html<\/a><\/p>\n<p>Sintaxe do arquivo de pol\u00edticas do Java:\u00a0<a href=\"http:\/\/docs.oracle.com\/javase\/6\/docs\/technotes\/guides\/security\/PolicyFiles.html\">http:\/\/docs.oracle.com\/javase\/6\/docs\/technotes\/guides\/security\/PolicyFiles.html<\/a><\/p>\n<p>Lista completa de pol\u00edticas de seguran\u00e7a padr\u00e3o do Java:\u00a0<a href=\"http:\/\/docs.oracle.com\/javase\/7\/docs\/technotes\/guides\/security\/permissions.html\">http:\/\/docs.oracle.com\/javase\/7\/docs\/technotes\/guides\/security\/permissions.html<\/a><\/p>\n<p>Post excelente sobre como aplicar as pol\u00edticas de seguran\u00e7a do Java em scripts Groovy:\u00a0<a href=\"http:\/\/www.chrismoos.com\/2010\/03\/24\/groovy-scripts-and-jvm-security\">http:\/\/www.chrismoos.com\/2010\/03\/24\/groovy-scripts-and-jvm-security<\/a><\/p>\n<p>O que a documenta\u00e7\u00e3o oficial do Groovy tem a dizer sobre o security manager:\u00a0<a href=\"http:\/\/groovy.codehaus.org\/Security\">http:\/\/groovy.codehaus.org\/Security<\/a><\/p>\n<h2>Acesso ao c\u00f3digo fonte<\/h2>\n<p>Est\u00e1 tudo no GitHub. Eis a URL do reposit\u00f3rio:\u00a0<a href=\"https:\/\/github.com\/loboweissmann\/groovy-grails-na-pratica\">https:\/\/github.com\/loboweissmann\/groovy-grails-na-pratica<\/a>.<br \/>\nBusque pela pasta &#8220;embarcando_groovy_seguranca&#8221;<\/p>\n<h2>E o v\u00eddeo?<\/h2>\n<p>Ah, o link \u00e9 este aqui:\u00a0<a href=\"http:\/\/www.youtube.com\/watch?v=8egPIoqsuLI\">http:\/\/www.youtube.com\/watch?v=8egPIoqsuLI<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>O Security Manager \u00e9 a piscina do javeiro: aquele recurso que diversas plataformas computacionais sonham possuir e muitos de n\u00f3s simplesmente ignoramos. Neste v\u00eddeo irei mostrar bem por alto o que v\u00eam a ser este recurso e como voc\u00ea pode us\u00e1-lo para executar seus scripts em um ambiente isolado, impedindo assim diversas amea\u00e7as que vimos [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":1473,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_coblocks_attr":"","_coblocks_dimensions":"","_coblocks_responsive_height":"","_coblocks_accordion_ie_support":"","site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-gradient":""}},"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[5],"tags":[],"class_list":["post-1472","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-groovy"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v22.8 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Melhorando a seguran\u00e7a de scripts na JVM: com voc\u00eas o Security Manager! - \/dev\/Kico<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/devkico.itexto.com.br\/?p=1472\" \/>\n<meta property=\"og:locale\" content=\"pt_BR\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Melhorando a seguran\u00e7a de scripts na JVM: com voc\u00eas o Security Manager! - \/dev\/Kico\" \/>\n<meta property=\"og:description\" content=\"O Security Manager \u00e9 a piscina do javeiro: aquele recurso que diversas plataformas computacionais sonham possuir e muitos de n\u00f3s simplesmente ignoramos. Neste v\u00eddeo irei mostrar bem por alto o que v\u00eam a ser este recurso e como voc\u00ea pode us\u00e1-lo para executar seus scripts em um ambiente isolado, impedindo assim diversas amea\u00e7as que vimos [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/devkico.itexto.com.br\/?p=1472\" \/>\n<meta property=\"og:site_name\" content=\"\/dev\/Kico\" \/>\n<meta property=\"article:published_time\" content=\"2013-08-13T02:44:34+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2013-08-13T02:48:18+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/devkico.itexto.com.br\/wp-content\/uploads\/2013\/08\/securityManager.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"300\" \/>\n\t<meta property=\"og:image:height\" content=\"169\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Kico (Henrique Lobo Weissmann)\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@loboweissmann\" \/>\n<meta name=\"twitter:label1\" content=\"Escrito por\" \/>\n\t<meta name=\"twitter:data1\" content=\"Kico (Henrique Lobo Weissmann)\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. tempo de leitura\" \/>\n\t<meta name=\"twitter:data2\" content=\"1 minuto\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/devkico.itexto.com.br\/?p=1472\",\"url\":\"https:\/\/devkico.itexto.com.br\/?p=1472\",\"name\":\"Melhorando a seguran\u00e7a de scripts na JVM: com voc\u00eas o Security Manager! - \/dev\/Kico\",\"isPartOf\":{\"@id\":\"https:\/\/devkico.itexto.com.br\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/devkico.itexto.com.br\/?p=1472#primaryimage\"},\"image\":{\"@id\":\"https:\/\/devkico.itexto.com.br\/?p=1472#primaryimage\"},\"thumbnailUrl\":\"https:\/\/devkico.itexto.com.br\/wp-content\/uploads\/2013\/08\/securityManager.jpg\",\"datePublished\":\"2013-08-13T02:44:34+00:00\",\"dateModified\":\"2013-08-13T02:48:18+00:00\",\"author\":{\"@id\":\"https:\/\/devkico.itexto.com.br\/#\/schema\/person\/502ab8892631bb005d6da2269fe5a3a7\"},\"breadcrumb\":{\"@id\":\"https:\/\/devkico.itexto.com.br\/?p=1472#breadcrumb\"},\"inLanguage\":\"pt-BR\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/devkico.itexto.com.br\/?p=1472\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"pt-BR\",\"@id\":\"https:\/\/devkico.itexto.com.br\/?p=1472#primaryimage\",\"url\":\"https:\/\/devkico.itexto.com.br\/wp-content\/uploads\/2013\/08\/securityManager.jpg\",\"contentUrl\":\"https:\/\/devkico.itexto.com.br\/wp-content\/uploads\/2013\/08\/securityManager.jpg\",\"width\":300,\"height\":169},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/devkico.itexto.com.br\/?p=1472#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/devkico.itexto.com.br\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Melhorando a seguran\u00e7a de scripts na JVM: com voc\u00eas o Security Manager!\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/devkico.itexto.com.br\/#website\",\"url\":\"https:\/\/devkico.itexto.com.br\/\",\"name\":\"\/dev\/Kico\",\"description\":\"Desenvolvendo software\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/devkico.itexto.com.br\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"pt-BR\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/devkico.itexto.com.br\/#\/schema\/person\/502ab8892631bb005d6da2269fe5a3a7\",\"name\":\"Kico (Henrique Lobo Weissmann)\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"pt-BR\",\"@id\":\"https:\/\/devkico.itexto.com.br\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/dd6973d86a689bc63122b2e603f25be3?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/dd6973d86a689bc63122b2e603f25be3?s=96&d=mm&r=g\",\"caption\":\"Kico (Henrique Lobo Weissmann)\"},\"sameAs\":[\"https:\/\/x.com\/loboweissmann\"],\"url\":\"https:\/\/devkico.itexto.com.br\/?author=1\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Melhorando a seguran\u00e7a de scripts na JVM: com voc\u00eas o Security Manager! - \/dev\/Kico","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/devkico.itexto.com.br\/?p=1472","og_locale":"pt_BR","og_type":"article","og_title":"Melhorando a seguran\u00e7a de scripts na JVM: com voc\u00eas o Security Manager! - \/dev\/Kico","og_description":"O Security Manager \u00e9 a piscina do javeiro: aquele recurso que diversas plataformas computacionais sonham possuir e muitos de n\u00f3s simplesmente ignoramos. Neste v\u00eddeo irei mostrar bem por alto o que v\u00eam a ser este recurso e como voc\u00ea pode us\u00e1-lo para executar seus scripts em um ambiente isolado, impedindo assim diversas amea\u00e7as que vimos [&hellip;]","og_url":"https:\/\/devkico.itexto.com.br\/?p=1472","og_site_name":"\/dev\/Kico","article_published_time":"2013-08-13T02:44:34+00:00","article_modified_time":"2013-08-13T02:48:18+00:00","og_image":[{"width":300,"height":169,"url":"https:\/\/devkico.itexto.com.br\/wp-content\/uploads\/2013\/08\/securityManager.jpg","type":"image\/jpeg"}],"author":"Kico (Henrique Lobo Weissmann)","twitter_card":"summary_large_image","twitter_creator":"@loboweissmann","twitter_misc":{"Escrito por":"Kico (Henrique Lobo Weissmann)","Est. tempo de leitura":"1 minuto"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/devkico.itexto.com.br\/?p=1472","url":"https:\/\/devkico.itexto.com.br\/?p=1472","name":"Melhorando a seguran\u00e7a de scripts na JVM: com voc\u00eas o Security Manager! - \/dev\/Kico","isPartOf":{"@id":"https:\/\/devkico.itexto.com.br\/#website"},"primaryImageOfPage":{"@id":"https:\/\/devkico.itexto.com.br\/?p=1472#primaryimage"},"image":{"@id":"https:\/\/devkico.itexto.com.br\/?p=1472#primaryimage"},"thumbnailUrl":"https:\/\/devkico.itexto.com.br\/wp-content\/uploads\/2013\/08\/securityManager.jpg","datePublished":"2013-08-13T02:44:34+00:00","dateModified":"2013-08-13T02:48:18+00:00","author":{"@id":"https:\/\/devkico.itexto.com.br\/#\/schema\/person\/502ab8892631bb005d6da2269fe5a3a7"},"breadcrumb":{"@id":"https:\/\/devkico.itexto.com.br\/?p=1472#breadcrumb"},"inLanguage":"pt-BR","potentialAction":[{"@type":"ReadAction","target":["https:\/\/devkico.itexto.com.br\/?p=1472"]}]},{"@type":"ImageObject","inLanguage":"pt-BR","@id":"https:\/\/devkico.itexto.com.br\/?p=1472#primaryimage","url":"https:\/\/devkico.itexto.com.br\/wp-content\/uploads\/2013\/08\/securityManager.jpg","contentUrl":"https:\/\/devkico.itexto.com.br\/wp-content\/uploads\/2013\/08\/securityManager.jpg","width":300,"height":169},{"@type":"BreadcrumbList","@id":"https:\/\/devkico.itexto.com.br\/?p=1472#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/devkico.itexto.com.br\/"},{"@type":"ListItem","position":2,"name":"Melhorando a seguran\u00e7a de scripts na JVM: com voc\u00eas o Security Manager!"}]},{"@type":"WebSite","@id":"https:\/\/devkico.itexto.com.br\/#website","url":"https:\/\/devkico.itexto.com.br\/","name":"\/dev\/Kico","description":"Desenvolvendo software","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/devkico.itexto.com.br\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"pt-BR"},{"@type":"Person","@id":"https:\/\/devkico.itexto.com.br\/#\/schema\/person\/502ab8892631bb005d6da2269fe5a3a7","name":"Kico (Henrique Lobo Weissmann)","image":{"@type":"ImageObject","inLanguage":"pt-BR","@id":"https:\/\/devkico.itexto.com.br\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/dd6973d86a689bc63122b2e603f25be3?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/dd6973d86a689bc63122b2e603f25be3?s=96&d=mm&r=g","caption":"Kico (Henrique Lobo Weissmann)"},"sameAs":["https:\/\/x.com\/loboweissmann"],"url":"https:\/\/devkico.itexto.com.br\/?author=1"}]}},"jetpack_featured_media_url":"https:\/\/devkico.itexto.com.br\/wp-content\/uploads\/2013\/08\/securityManager.jpg","jetpack-related-posts":[],"jetpack_sharing_enabled":true,"jetpack_likes_enabled":true,"_links":{"self":[{"href":"https:\/\/devkico.itexto.com.br\/index.php?rest_route=\/wp\/v2\/posts\/1472"}],"collection":[{"href":"https:\/\/devkico.itexto.com.br\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/devkico.itexto.com.br\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/devkico.itexto.com.br\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/devkico.itexto.com.br\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1472"}],"version-history":[{"count":3,"href":"https:\/\/devkico.itexto.com.br\/index.php?rest_route=\/wp\/v2\/posts\/1472\/revisions"}],"predecessor-version":[{"id":1476,"href":"https:\/\/devkico.itexto.com.br\/index.php?rest_route=\/wp\/v2\/posts\/1472\/revisions\/1476"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/devkico.itexto.com.br\/index.php?rest_route=\/wp\/v2\/media\/1473"}],"wp:attachment":[{"href":"https:\/\/devkico.itexto.com.br\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1472"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/devkico.itexto.com.br\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1472"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/devkico.itexto.com.br\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1472"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}