{"id":30999,"date":"2024-12-09T14:13:29","date_gmt":"2024-12-09T13:13:29","guid":{"rendered":"https:\/\/www.codemotion.com\/magazine\/?p=30999"},"modified":"2025-02-06T12:15:41","modified_gmt":"2025-02-06T11:15:41","slug":"scrivere-codice-sicuro-la-guida-essenziale-per-gli-sviluppatori-java","status":"publish","type":"post","link":"https:\/\/www.codemotion.com\/magazine\/it\/cybersecurity-it\/scrivere-codice-sicuro-la-guida-essenziale-per-gli-sviluppatori-java\/","title":{"rendered":"Scrivere codice sicuro: la guida essenziale per gli sviluppatori java &#8211; Parte 1"},"content":{"rendered":"\n<p>La sicurezza del codice non \u00e8 un optional: \u00e8 una responsabilit\u00e0 essenziale di ogni sviluppatore. Questo articolo inaugura una serie dedicata a <strong>come scrivere codice sicuro<\/strong>, affrontando una delle minacce pi\u00f9 diffuse e pericolose nello sviluppo di applicazioni: <strong>le SQL Injection<\/strong>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-cos-e-una-sql-injection\"><strong>Cos&#8217;\u00e8 una SQL Injection?<\/strong><\/h2>\n\n\n\n<p>La <strong>SQL Injection<\/strong> \u00e8 un attacco in cui un utente malintenzionato manipola le query SQL inviate a un database attraverso input non controllati.<\/p>\n\n\n\n<p>Questo avviene quando l&#8217;applicazione non valida correttamente i dati forniti dall&#8217;utente e consente a query malevole di essere eseguite, senza quindi alcun controllo su di esse, con conseguenze potenzialmente devastanti.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-cosa-puo-succedere-in-caso-di-sql-injection\"><strong>Cosa pu\u00f2 succedere in caso di SQL Injection?<\/strong><\/h3>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>Accesso non autorizzato ai dati<\/strong>: Gli attaccanti possono ottenere informazioni sensibili, come credenziali, dati personali o aziendali.<\/li>\n\n\n\n<li><strong>Manipolazione o cancellazione di dati<\/strong>: Una query malevola potrebbe alterare o eliminare dati cruciali.<\/li>\n\n\n\n<li><strong>Compromissione del sistema<\/strong>: In alcuni casi, l&#8217;attaccante pu\u00f2 eseguire comandi di sistema attraverso query SQL.<\/li>\n\n\n\n<li><strong>Impatto legale e reputazionale<\/strong>: La violazione di dati personali pu\u00f2 portare a sanzioni (es. GDPR) e alla perdita di fiducia da parte degli utenti.<\/li>\n<\/ol>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Esempio di SQL Injection<\/strong><\/h2>\n\n\n\n<p>Consideriamo un codice vulnerabile a SQL Injection:<\/p>\n\n\n<pre class=\"wp-block-code\" aria-describedby=\"shcb-language-1\" data-shcb-language-name=\"JavaScript\" data-shcb-language-slug=\"javascript\"><span><code class=\"hljs language-javascript\"><span class=\"hljs-built_in\">String<\/span> username = request.getParameter(<span class=\"hljs-string\">\"username\"<\/span>);\n<span class=\"hljs-built_in\">String<\/span> password = request.getParameter(<span class=\"hljs-string\">\"password\"<\/span>);\n\n<span class=\"hljs-built_in\">String<\/span> query = <span class=\"hljs-string\">\"SELECT * FROM users WHERE username = '\"<\/span> + username + <span class=\"hljs-string\">\"' AND password = '\"<\/span> + password + <span class=\"hljs-string\">\"'\"<\/span>;\n\nStatement stmt = connection.createStatement();\nResultSet rs = stmt.executeQuery(query);\n<\/code><\/span><small class=\"shcb-language\" id=\"shcb-language-1\"><span class=\"shcb-language__label\">Code language:<\/span> <span class=\"shcb-language__name\">JavaScript<\/span> <span class=\"shcb-language__paren\">(<\/span><span class=\"shcb-language__slug\">javascript<\/span><span class=\"shcb-language__paren\">)<\/span><\/small><\/pre>\n\n\n<p>Se un utente inserisce come <code>username<\/code>:<\/p>\n\n\n<pre class=\"wp-block-code\" aria-describedby=\"shcb-language-2\" data-shcb-language-name=\"JavaScript\" data-shcb-language-slug=\"javascript\"><span><code class=\"hljs language-javascript\"><span class=\"hljs-string\">' OR '<\/span><span class=\"hljs-number\">1<\/span><span class=\"hljs-string\">'='<\/span><span class=\"hljs-number\">1<\/span>\n<\/code><\/span><small class=\"shcb-language\" id=\"shcb-language-2\"><span class=\"shcb-language__label\">Code language:<\/span> <span class=\"shcb-language__name\">JavaScript<\/span> <span class=\"shcb-language__paren\">(<\/span><span class=\"shcb-language__slug\">javascript<\/span><span class=\"shcb-language__paren\">)<\/span><\/small><\/pre>\n\n\n<p>La query risultante diventa:<\/p>\n\n\n<pre class=\"wp-block-code\" aria-describedby=\"shcb-language-3\" data-shcb-language-name=\"JavaScript\" data-shcb-language-slug=\"javascript\"><span><code class=\"hljs language-javascript\">SELECT * FROM users WHERE username = <span class=\"hljs-string\">''<\/span> OR <span class=\"hljs-string\">'1'<\/span>=<span class=\"hljs-string\">'1'<\/span> AND password = <span class=\"hljs-string\">''<\/span>\n<\/code><\/span><small class=\"shcb-language\" id=\"shcb-language-3\"><span class=\"shcb-language__label\">Code language:<\/span> <span class=\"shcb-language__name\">JavaScript<\/span> <span class=\"shcb-language__paren\">(<\/span><span class=\"shcb-language__slug\">javascript<\/span><span class=\"shcb-language__paren\">)<\/span><\/small><\/pre>\n\n\n<p>Questa condizione sar\u00e0 sempre vera, permettendo l&#8217;accesso non autorizzato in quanto la condizione &#8216;1&#8217;=&#8217;1&#8242; \u00e8 sempre vera e  di conseguenza tutte le condizioni che sono scritte prima o dopo questa <em>OR clause<\/em> sono inutili, pertanto \u00e8 stato rotto il meccanismo di controllo su username e password, in questo caso.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Come prevenire le SQL Injection in <a href=\"https:\/\/www.codemotion.com\/magazine\/it\/backend-it\/ottimizzazione-delle-prestazioni-in-java-guida-pratica\/\">Java<\/a><\/strong><\/h2>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>1. Usa Prepared Statements<\/strong><\/h4>\n\n\n\n<p>I <strong>Prepared Statements<\/strong> (o query parametrizzate) evitano che l&#8217;input dell&#8217;utente venga interpretato come parte del codice SQL.<\/p>\n\n\n\n<p>Esempio corretto:<\/p>\n\n\n<pre class=\"wp-block-code\" aria-describedby=\"shcb-language-4\" data-shcb-language-name=\"JavaScript\" data-shcb-language-slug=\"javascript\"><span><code class=\"hljs language-javascript\"><span class=\"hljs-built_in\">String<\/span> query = <span class=\"hljs-string\">\"SELECT * FROM users WHERE username = ? AND password = ?\"<\/span>;\nPreparedStatement pstmt = connection.prepareStatement(query);\n\npstmt.setString(<span class=\"hljs-number\">1<\/span>, username);\npstmt.setString(<span class=\"hljs-number\">2<\/span>, password);\n\nResultSet rs = pstmt.executeQuery();\n<\/code><\/span><small class=\"shcb-language\" id=\"shcb-language-4\"><span class=\"shcb-language__label\">Code language:<\/span> <span class=\"shcb-language__name\">JavaScript<\/span> <span class=\"shcb-language__paren\">(<\/span><span class=\"shcb-language__slug\">javascript<\/span><span class=\"shcb-language__paren\">)<\/span><\/small><\/pre>\n\n\n<p>In questo caso, qualsiasi input verr\u00e0 trattato come dato e non come comando SQL.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>2. Usa ORM (Object Relational Mapping)<\/strong><\/h4>\n\n\n\n<p>Framework come <strong>Hibernate<\/strong> o <strong>JPA<\/strong> astraggono le query SQL, riducendo il rischio di SQL Injection.<\/p>\n\n\n\n<p>Esempio con Hibernate:<\/p>\n\n\n<pre class=\"wp-block-code\" aria-describedby=\"shcb-language-5\" data-shcb-language-name=\"JavaScript\" data-shcb-language-slug=\"javascript\"><span><code class=\"hljs language-javascript\">User user = session.createQuery(<span class=\"hljs-string\">\"FROM User WHERE username = :username AND password = :password\"<\/span>, User.class)\n                   .setParameter(<span class=\"hljs-string\">\"username\"<\/span>, username)\n                   .setParameter(<span class=\"hljs-string\">\"password\"<\/span>, password)\n                   .uniqueResult();\n<\/code><\/span><small class=\"shcb-language\" id=\"shcb-language-5\"><span class=\"shcb-language__label\">Code language:<\/span> <span class=\"shcb-language__name\">JavaScript<\/span> <span class=\"shcb-language__paren\">(<\/span><span class=\"shcb-language__slug\">javascript<\/span><span class=\"shcb-language__paren\">)<\/span><\/small><\/pre>\n\n\n<h4 class=\"wp-block-heading\"><strong>3. Valida l&#8217;input<\/strong><\/h4>\n\n\n\n<p>Non fidarti mai dell&#8217;input dell&#8217;utente. Utilizza librerie per la validazione (es. Apache Commons Validator) e limita i caratteri consentiti.<\/p>\n\n\n\n<p>Esempio:<\/p>\n\n\n<pre class=\"wp-block-code\" aria-describedby=\"shcb-language-6\" data-shcb-language-name=\"JavaScript\" data-shcb-language-slug=\"javascript\"><span><code class=\"hljs language-javascript\"><span class=\"hljs-keyword\">if<\/span> (!username.matches(<span class=\"hljs-string\">\"&#91;a-zA-Z0-9_]+\"<\/span>)) {\n    <span class=\"hljs-keyword\">throw<\/span> <span class=\"hljs-keyword\">new<\/span> IllegalArgumentException(<span class=\"hljs-string\">\"Username contiene caratteri non validi.\"<\/span>);\n}\n<\/code><\/span><small class=\"shcb-language\" id=\"shcb-language-6\"><span class=\"shcb-language__label\">Code language:<\/span> <span class=\"shcb-language__name\">JavaScript<\/span> <span class=\"shcb-language__paren\">(<\/span><span class=\"shcb-language__slug\">javascript<\/span><span class=\"shcb-language__paren\">)<\/span><\/small><\/pre>\n\n\n<h4 class=\"wp-block-heading\"><strong>4. Configura correttamente il database<\/strong><\/h4>\n\n\n\n<p>Un database configurato correttamente pu\u00f2 limitare i danni di un attacco SQL Injection:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Usa un account con privilegi limitati<\/strong> per accedere al database.<\/li>\n\n\n\n<li><strong>Abilita log di sicurezza<\/strong> per monitorare attivit\u00e0 sospette.<\/li>\n\n\n\n<li><strong>Sanitizza i dati memorizzati<\/strong>, per evitare che dati malevoli vengano iniettati in seguito.<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>5. Usa librerie di sicurezza<\/strong><\/h4>\n\n\n\n<p>Esistono librerie dedicate a proteggere le applicazioni da vulnerabilit\u00e0 comuni:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>OWASP ESAPI<\/strong>: fornisce metodi per validare input e prevenire SQL Injection.<\/li>\n\n\n\n<li><strong>Spring Security<\/strong>: integra strumenti per proteggere applicazioni Spring, incluso il controllo di accesso al database.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Conclusioni<\/strong><\/h2>\n\n\n\n<p>La SQL Injection \u00e8 una minaccia reale, ma con le giuste pratiche pu\u00f2 essere evitata. L&#8217;uso di <strong>Prepared Statements<\/strong>, <strong>ORM<\/strong>, e la <strong>validazione dell&#8217;input<\/strong> sono strumenti indispensabili per scrivere codice sicuro.<\/p>\n\n\n\n<p>Nel prossimo articolo di questa serie, approfondiremo un&#8217;altra vulnerabilit\u00e0 critica: <strong>il Cross-Site Scripting (XSS)<\/strong>. Fino ad allora, ricorda: il codice sicuro \u00e8 la tua prima linea di difesa.<\/p>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>La sicurezza del codice non \u00e8 un optional: \u00e8 una responsabilit\u00e0 essenziale di ogni sviluppatore. Questo articolo inaugura una serie dedicata a come scrivere codice sicuro, affrontando una delle minacce pi\u00f9 diffuse e pericolose nello sviluppo di applicazioni: le SQL Injection. Cos&#8217;\u00e8 una SQL Injection? La SQL Injection \u00e8 un attacco in cui un utente&#8230; <a class=\"more-link\" href=\"https:\/\/www.codemotion.com\/magazine\/it\/cybersecurity-it\/scrivere-codice-sicuro-la-guida-essenziale-per-gli-sviluppatori-java\/\">Read more<\/a><\/p>\n","protected":false},"author":218,"featured_media":31041,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_editorskit_title_hidden":false,"_editorskit_reading_time":0,"_editorskit_is_block_options_detached":false,"_editorskit_block_options_position":"{}","_uag_custom_page_level_css":"","_genesis_hide_title":false,"_genesis_hide_breadcrumbs":false,"_genesis_hide_singular_image":false,"_genesis_hide_footer_widgets":false,"_genesis_custom_body_class":"","_genesis_custom_post_class":"","_genesis_layout":"","footnotes":""},"categories":[10228],"tags":[12854,10329,10438],"collections":[11708],"class_list":{"0":"post-30999","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-cybersecurity-it","8":"tag-backend-it","9":"tag-framework","10":"tag-sviluppo-software-it","11":"collections-dalla-community","12":"entry"},"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v26.9 (Yoast SEO v27.5) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Scrivere codice sicuro: la guida essenziale per gli sviluppatori java - Parte 1<\/title>\n<meta name=\"description\" content=\"Questo articolo affronta una delle minacce pi\u00f9 comuni e insidiose nello sviluppo di applicazioni: le SQL Injection.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.codemotion.com\/magazine\/it\/cybersecurity-it\/scrivere-codice-sicuro-la-guida-essenziale-per-gli-sviluppatori-java\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Scrivere codice sicuro: la guida essenziale per gli sviluppatori java - Parte 1\" \/>\n<meta property=\"og:description\" content=\"Questo articolo affronta una delle minacce pi\u00f9 comuni e insidiose nello sviluppo di applicazioni: le SQL Injection.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.codemotion.com\/magazine\/it\/cybersecurity-it\/scrivere-codice-sicuro-la-guida-essenziale-per-gli-sviluppatori-java\/\" \/>\n<meta property=\"og:site_name\" content=\"Codemotion Magazine\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Codemotion.Italy\/\" \/>\n<meta property=\"article:published_time\" content=\"2024-12-09T13:13:29+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-02-06T11:15:41+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.codemotion.com\/magazine\/wp-content\/uploads\/2024\/12\/DALL\u00b7E-2024-12-09-14.08.18-A-horizontal-scene-depicting-the-concept-of-cybersecurity-in-a-visually-stunning-futuristic-style.-The-image-features-a-central-glowing-shield-symbol.webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1792\" \/>\n\t<meta property=\"og:image:height\" content=\"1024\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/webp\" \/>\n<meta name=\"author\" content=\"peduz91\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@peduz91\" \/>\n<meta name=\"twitter:site\" content=\"@CodemotionIT\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"peduz91\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.codemotion.com\\\/magazine\\\/it\\\/cybersecurity-it\\\/scrivere-codice-sicuro-la-guida-essenziale-per-gli-sviluppatori-java\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.codemotion.com\\\/magazine\\\/it\\\/cybersecurity-it\\\/scrivere-codice-sicuro-la-guida-essenziale-per-gli-sviluppatori-java\\\/\"},\"author\":{\"name\":\"peduz91\",\"@id\":\"https:\\\/\\\/www.codemotion.com\\\/magazine\\\/#\\\/schema\\\/person\\\/452ca8d6219835e3b83660c0c86dfb98\"},\"headline\":\"Scrivere codice sicuro: la guida essenziale per gli sviluppatori java &#8211; Parte 1\",\"datePublished\":\"2024-12-09T13:13:29+00:00\",\"dateModified\":\"2025-02-06T11:15:41+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.codemotion.com\\\/magazine\\\/it\\\/cybersecurity-it\\\/scrivere-codice-sicuro-la-guida-essenziale-per-gli-sviluppatori-java\\\/\"},\"wordCount\":489,\"publisher\":{\"@id\":\"https:\\\/\\\/www.codemotion.com\\\/magazine\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.codemotion.com\\\/magazine\\\/it\\\/cybersecurity-it\\\/scrivere-codice-sicuro-la-guida-essenziale-per-gli-sviluppatori-java\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.codemotion.com\\\/magazine\\\/wp-content\\\/uploads\\\/2024\\\/12\\\/DALL\u00b7E-2024-12-09-14.08.18-A-horizontal-scene-depicting-the-concept-of-cybersecurity-in-a-visually-stunning-futuristic-style.-The-image-features-a-central-glowing-shield-symbol.webp\",\"keywords\":[\"Backend\",\"Framework\",\"sviluppo software\"],\"articleSection\":[\"Cybersecurity\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.codemotion.com\\\/magazine\\\/it\\\/cybersecurity-it\\\/scrivere-codice-sicuro-la-guida-essenziale-per-gli-sviluppatori-java\\\/\",\"url\":\"https:\\\/\\\/www.codemotion.com\\\/magazine\\\/it\\\/cybersecurity-it\\\/scrivere-codice-sicuro-la-guida-essenziale-per-gli-sviluppatori-java\\\/\",\"name\":\"Scrivere codice sicuro: la guida essenziale per gli sviluppatori java - Parte 1\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.codemotion.com\\\/magazine\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.codemotion.com\\\/magazine\\\/it\\\/cybersecurity-it\\\/scrivere-codice-sicuro-la-guida-essenziale-per-gli-sviluppatori-java\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.codemotion.com\\\/magazine\\\/it\\\/cybersecurity-it\\\/scrivere-codice-sicuro-la-guida-essenziale-per-gli-sviluppatori-java\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.codemotion.com\\\/magazine\\\/wp-content\\\/uploads\\\/2024\\\/12\\\/DALL\u00b7E-2024-12-09-14.08.18-A-horizontal-scene-depicting-the-concept-of-cybersecurity-in-a-visually-stunning-futuristic-style.-The-image-features-a-central-glowing-shield-symbol.webp\",\"datePublished\":\"2024-12-09T13:13:29+00:00\",\"dateModified\":\"2025-02-06T11:15:41+00:00\",\"description\":\"Questo articolo affronta una delle minacce pi\u00f9 comuni e insidiose nello sviluppo di applicazioni: le SQL Injection.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.codemotion.com\\\/magazine\\\/it\\\/cybersecurity-it\\\/scrivere-codice-sicuro-la-guida-essenziale-per-gli-sviluppatori-java\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.codemotion.com\\\/magazine\\\/it\\\/cybersecurity-it\\\/scrivere-codice-sicuro-la-guida-essenziale-per-gli-sviluppatori-java\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.codemotion.com\\\/magazine\\\/it\\\/cybersecurity-it\\\/scrivere-codice-sicuro-la-guida-essenziale-per-gli-sviluppatori-java\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.codemotion.com\\\/magazine\\\/wp-content\\\/uploads\\\/2024\\\/12\\\/DALL\u00b7E-2024-12-09-14.08.18-A-horizontal-scene-depicting-the-concept-of-cybersecurity-in-a-visually-stunning-futuristic-style.-The-image-features-a-central-glowing-shield-symbol.webp\",\"contentUrl\":\"https:\\\/\\\/www.codemotion.com\\\/magazine\\\/wp-content\\\/uploads\\\/2024\\\/12\\\/DALL\u00b7E-2024-12-09-14.08.18-A-horizontal-scene-depicting-the-concept-of-cybersecurity-in-a-visually-stunning-futuristic-style.-The-image-features-a-central-glowing-shield-symbol.webp\",\"width\":1792,\"height\":1024},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.codemotion.com\\\/magazine\\\/it\\\/cybersecurity-it\\\/scrivere-codice-sicuro-la-guida-essenziale-per-gli-sviluppatori-java\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.codemotion.com\\\/magazine\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Cybersecurity\",\"item\":\"https:\\\/\\\/www.codemotion.com\\\/magazine\\\/it\\\/cybersecurity-it\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Scrivere codice sicuro: la guida essenziale per gli sviluppatori java &#8211; Parte 1\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.codemotion.com\\\/magazine\\\/#website\",\"url\":\"https:\\\/\\\/www.codemotion.com\\\/magazine\\\/\",\"name\":\"Codemotion Magazine\",\"description\":\"We code the future. Together\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.codemotion.com\\\/magazine\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.codemotion.com\\\/magazine\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.codemotion.com\\\/magazine\\\/#organization\",\"name\":\"Codemotion\",\"url\":\"https:\\\/\\\/www.codemotion.com\\\/magazine\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.codemotion.com\\\/magazine\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.codemotion.com\\\/magazine\\\/wp-content\\\/uploads\\\/2019\\\/11\\\/codemotionlogo.png\",\"contentUrl\":\"https:\\\/\\\/www.codemotion.com\\\/magazine\\\/wp-content\\\/uploads\\\/2019\\\/11\\\/codemotionlogo.png\",\"width\":225,\"height\":225,\"caption\":\"Codemotion\"},\"image\":{\"@id\":\"https:\\\/\\\/www.codemotion.com\\\/magazine\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/Codemotion.Italy\\\/\",\"https:\\\/\\\/x.com\\\/CodemotionIT\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.codemotion.com\\\/magazine\\\/#\\\/schema\\\/person\\\/452ca8d6219835e3b83660c0c86dfb98\",\"name\":\"peduz91\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.codemotion.com\\\/magazine\\\/wp-content\\\/uploads\\\/2023\\\/12\\\/gp-100x100.jpg\",\"url\":\"https:\\\/\\\/www.codemotion.com\\\/magazine\\\/wp-content\\\/uploads\\\/2023\\\/12\\\/gp-100x100.jpg\",\"contentUrl\":\"https:\\\/\\\/www.codemotion.com\\\/magazine\\\/wp-content\\\/uploads\\\/2023\\\/12\\\/gp-100x100.jpg\",\"caption\":\"peduz91\"},\"description\":\"I am a software developer with a strong passion for development, technology, soccer and chess. I always like to challenge myself, I often try new things. I think the most important thing is to work well with the team.\",\"sameAs\":[\"https:\\\/\\\/www.linkedin.com\\\/in\\\/giuseppe-pedull-68ab8274\\\/\",\"https:\\\/\\\/x.com\\\/peduz91\"],\"url\":\"https:\\\/\\\/www.codemotion.com\\\/magazine\\\/author\\\/peduz91\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Scrivere codice sicuro: la guida essenziale per gli sviluppatori java - Parte 1","description":"Questo articolo affronta una delle minacce pi\u00f9 comuni e insidiose nello sviluppo di applicazioni: le SQL Injection.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.codemotion.com\/magazine\/it\/cybersecurity-it\/scrivere-codice-sicuro-la-guida-essenziale-per-gli-sviluppatori-java\/","og_locale":"en_US","og_type":"article","og_title":"Scrivere codice sicuro: la guida essenziale per gli sviluppatori java - Parte 1","og_description":"Questo articolo affronta una delle minacce pi\u00f9 comuni e insidiose nello sviluppo di applicazioni: le SQL Injection.","og_url":"https:\/\/www.codemotion.com\/magazine\/it\/cybersecurity-it\/scrivere-codice-sicuro-la-guida-essenziale-per-gli-sviluppatori-java\/","og_site_name":"Codemotion Magazine","article_publisher":"https:\/\/www.facebook.com\/Codemotion.Italy\/","article_published_time":"2024-12-09T13:13:29+00:00","article_modified_time":"2025-02-06T11:15:41+00:00","og_image":[{"width":1792,"height":1024,"url":"https:\/\/www.codemotion.com\/magazine\/wp-content\/uploads\/2024\/12\/DALL\u00b7E-2024-12-09-14.08.18-A-horizontal-scene-depicting-the-concept-of-cybersecurity-in-a-visually-stunning-futuristic-style.-The-image-features-a-central-glowing-shield-symbol.webp","type":"image\/webp"}],"author":"peduz91","twitter_card":"summary_large_image","twitter_creator":"@peduz91","twitter_site":"@CodemotionIT","twitter_misc":{"Written by":"peduz91","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.codemotion.com\/magazine\/it\/cybersecurity-it\/scrivere-codice-sicuro-la-guida-essenziale-per-gli-sviluppatori-java\/#article","isPartOf":{"@id":"https:\/\/www.codemotion.com\/magazine\/it\/cybersecurity-it\/scrivere-codice-sicuro-la-guida-essenziale-per-gli-sviluppatori-java\/"},"author":{"name":"peduz91","@id":"https:\/\/www.codemotion.com\/magazine\/#\/schema\/person\/452ca8d6219835e3b83660c0c86dfb98"},"headline":"Scrivere codice sicuro: la guida essenziale per gli sviluppatori java &#8211; Parte 1","datePublished":"2024-12-09T13:13:29+00:00","dateModified":"2025-02-06T11:15:41+00:00","mainEntityOfPage":{"@id":"https:\/\/www.codemotion.com\/magazine\/it\/cybersecurity-it\/scrivere-codice-sicuro-la-guida-essenziale-per-gli-sviluppatori-java\/"},"wordCount":489,"publisher":{"@id":"https:\/\/www.codemotion.com\/magazine\/#organization"},"image":{"@id":"https:\/\/www.codemotion.com\/magazine\/it\/cybersecurity-it\/scrivere-codice-sicuro-la-guida-essenziale-per-gli-sviluppatori-java\/#primaryimage"},"thumbnailUrl":"https:\/\/www.codemotion.com\/magazine\/wp-content\/uploads\/2024\/12\/DALL\u00b7E-2024-12-09-14.08.18-A-horizontal-scene-depicting-the-concept-of-cybersecurity-in-a-visually-stunning-futuristic-style.-The-image-features-a-central-glowing-shield-symbol.webp","keywords":["Backend","Framework","sviluppo software"],"articleSection":["Cybersecurity"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.codemotion.com\/magazine\/it\/cybersecurity-it\/scrivere-codice-sicuro-la-guida-essenziale-per-gli-sviluppatori-java\/","url":"https:\/\/www.codemotion.com\/magazine\/it\/cybersecurity-it\/scrivere-codice-sicuro-la-guida-essenziale-per-gli-sviluppatori-java\/","name":"Scrivere codice sicuro: la guida essenziale per gli sviluppatori java - Parte 1","isPartOf":{"@id":"https:\/\/www.codemotion.com\/magazine\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.codemotion.com\/magazine\/it\/cybersecurity-it\/scrivere-codice-sicuro-la-guida-essenziale-per-gli-sviluppatori-java\/#primaryimage"},"image":{"@id":"https:\/\/www.codemotion.com\/magazine\/it\/cybersecurity-it\/scrivere-codice-sicuro-la-guida-essenziale-per-gli-sviluppatori-java\/#primaryimage"},"thumbnailUrl":"https:\/\/www.codemotion.com\/magazine\/wp-content\/uploads\/2024\/12\/DALL\u00b7E-2024-12-09-14.08.18-A-horizontal-scene-depicting-the-concept-of-cybersecurity-in-a-visually-stunning-futuristic-style.-The-image-features-a-central-glowing-shield-symbol.webp","datePublished":"2024-12-09T13:13:29+00:00","dateModified":"2025-02-06T11:15:41+00:00","description":"Questo articolo affronta una delle minacce pi\u00f9 comuni e insidiose nello sviluppo di applicazioni: le SQL Injection.","breadcrumb":{"@id":"https:\/\/www.codemotion.com\/magazine\/it\/cybersecurity-it\/scrivere-codice-sicuro-la-guida-essenziale-per-gli-sviluppatori-java\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.codemotion.com\/magazine\/it\/cybersecurity-it\/scrivere-codice-sicuro-la-guida-essenziale-per-gli-sviluppatori-java\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.codemotion.com\/magazine\/it\/cybersecurity-it\/scrivere-codice-sicuro-la-guida-essenziale-per-gli-sviluppatori-java\/#primaryimage","url":"https:\/\/www.codemotion.com\/magazine\/wp-content\/uploads\/2024\/12\/DALL\u00b7E-2024-12-09-14.08.18-A-horizontal-scene-depicting-the-concept-of-cybersecurity-in-a-visually-stunning-futuristic-style.-The-image-features-a-central-glowing-shield-symbol.webp","contentUrl":"https:\/\/www.codemotion.com\/magazine\/wp-content\/uploads\/2024\/12\/DALL\u00b7E-2024-12-09-14.08.18-A-horizontal-scene-depicting-the-concept-of-cybersecurity-in-a-visually-stunning-futuristic-style.-The-image-features-a-central-glowing-shield-symbol.webp","width":1792,"height":1024},{"@type":"BreadcrumbList","@id":"https:\/\/www.codemotion.com\/magazine\/it\/cybersecurity-it\/scrivere-codice-sicuro-la-guida-essenziale-per-gli-sviluppatori-java\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.codemotion.com\/magazine\/"},{"@type":"ListItem","position":2,"name":"Cybersecurity","item":"https:\/\/www.codemotion.com\/magazine\/it\/cybersecurity-it\/"},{"@type":"ListItem","position":3,"name":"Scrivere codice sicuro: la guida essenziale per gli sviluppatori java &#8211; Parte 1"}]},{"@type":"WebSite","@id":"https:\/\/www.codemotion.com\/magazine\/#website","url":"https:\/\/www.codemotion.com\/magazine\/","name":"Codemotion Magazine","description":"We code the future. Together","publisher":{"@id":"https:\/\/www.codemotion.com\/magazine\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.codemotion.com\/magazine\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.codemotion.com\/magazine\/#organization","name":"Codemotion","url":"https:\/\/www.codemotion.com\/magazine\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.codemotion.com\/magazine\/#\/schema\/logo\/image\/","url":"https:\/\/www.codemotion.com\/magazine\/wp-content\/uploads\/2019\/11\/codemotionlogo.png","contentUrl":"https:\/\/www.codemotion.com\/magazine\/wp-content\/uploads\/2019\/11\/codemotionlogo.png","width":225,"height":225,"caption":"Codemotion"},"image":{"@id":"https:\/\/www.codemotion.com\/magazine\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Codemotion.Italy\/","https:\/\/x.com\/CodemotionIT"]},{"@type":"Person","@id":"https:\/\/www.codemotion.com\/magazine\/#\/schema\/person\/452ca8d6219835e3b83660c0c86dfb98","name":"peduz91","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.codemotion.com\/magazine\/wp-content\/uploads\/2023\/12\/gp-100x100.jpg","url":"https:\/\/www.codemotion.com\/magazine\/wp-content\/uploads\/2023\/12\/gp-100x100.jpg","contentUrl":"https:\/\/www.codemotion.com\/magazine\/wp-content\/uploads\/2023\/12\/gp-100x100.jpg","caption":"peduz91"},"description":"I am a software developer with a strong passion for development, technology, soccer and chess. I always like to challenge myself, I often try new things. I think the most important thing is to work well with the team.","sameAs":["https:\/\/www.linkedin.com\/in\/giuseppe-pedull-68ab8274\/","https:\/\/x.com\/peduz91"],"url":"https:\/\/www.codemotion.com\/magazine\/author\/peduz91\/"}]}},"featured_image_src":"https:\/\/www.codemotion.com\/magazine\/wp-content\/uploads\/2024\/12\/DALL\u00b7E-2024-12-09-14.08.18-A-horizontal-scene-depicting-the-concept-of-cybersecurity-in-a-visually-stunning-futuristic-style.-The-image-features-a-central-glowing-shield-symbol-600x400.webp","featured_image_src_square":"https:\/\/www.codemotion.com\/magazine\/wp-content\/uploads\/2024\/12\/DALL\u00b7E-2024-12-09-14.08.18-A-horizontal-scene-depicting-the-concept-of-cybersecurity-in-a-visually-stunning-futuristic-style.-The-image-features-a-central-glowing-shield-symbol-600x600.webp","author_info":{"display_name":"peduz91","author_link":"https:\/\/www.codemotion.com\/magazine\/author\/peduz91\/"},"uagb_featured_image_src":{"full":["https:\/\/www.codemotion.com\/magazine\/wp-content\/uploads\/2024\/12\/DALL\u00b7E-2024-12-09-14.08.18-A-horizontal-scene-depicting-the-concept-of-cybersecurity-in-a-visually-stunning-futuristic-style.-The-image-features-a-central-glowing-shield-symbol.webp",1792,1024,false],"thumbnail":["https:\/\/www.codemotion.com\/magazine\/wp-content\/uploads\/2024\/12\/DALL\u00b7E-2024-12-09-14.08.18-A-horizontal-scene-depicting-the-concept-of-cybersecurity-in-a-visually-stunning-futuristic-style.-The-image-features-a-central-glowing-shield-symbol-150x150.webp",150,150,true],"medium":["https:\/\/www.codemotion.com\/magazine\/wp-content\/uploads\/2024\/12\/DALL\u00b7E-2024-12-09-14.08.18-A-horizontal-scene-depicting-the-concept-of-cybersecurity-in-a-visually-stunning-futuristic-style.-The-image-features-a-central-glowing-shield-symbol-300x171.webp",300,171,true],"medium_large":["https:\/\/www.codemotion.com\/magazine\/wp-content\/uploads\/2024\/12\/DALL\u00b7E-2024-12-09-14.08.18-A-horizontal-scene-depicting-the-concept-of-cybersecurity-in-a-visually-stunning-futuristic-style.-The-image-features-a-central-glowing-shield-symbol-768x439.webp",768,439,true],"large":["https:\/\/www.codemotion.com\/magazine\/wp-content\/uploads\/2024\/12\/DALL\u00b7E-2024-12-09-14.08.18-A-horizontal-scene-depicting-the-concept-of-cybersecurity-in-a-visually-stunning-futuristic-style.-The-image-features-a-central-glowing-shield-symbol-1024x585.webp",1024,585,true],"1536x1536":["https:\/\/www.codemotion.com\/magazine\/wp-content\/uploads\/2024\/12\/DALL\u00b7E-2024-12-09-14.08.18-A-horizontal-scene-depicting-the-concept-of-cybersecurity-in-a-visually-stunning-futuristic-style.-The-image-features-a-central-glowing-shield-symbol-1536x878.webp",1536,878,true],"2048x2048":["https:\/\/www.codemotion.com\/magazine\/wp-content\/uploads\/2024\/12\/DALL\u00b7E-2024-12-09-14.08.18-A-horizontal-scene-depicting-the-concept-of-cybersecurity-in-a-visually-stunning-futuristic-style.-The-image-features-a-central-glowing-shield-symbol.webp",1792,1024,false],"small-home-featured":["https:\/\/www.codemotion.com\/magazine\/wp-content\/uploads\/2024\/12\/DALL\u00b7E-2024-12-09-14.08.18-A-horizontal-scene-depicting-the-concept-of-cybersecurity-in-a-visually-stunning-futuristic-style.-The-image-features-a-central-glowing-shield-symbol-100x100.webp",100,100,true],"sidebar-featured":["https:\/\/www.codemotion.com\/magazine\/wp-content\/uploads\/2024\/12\/DALL\u00b7E-2024-12-09-14.08.18-A-horizontal-scene-depicting-the-concept-of-cybersecurity-in-a-visually-stunning-futuristic-style.-The-image-features-a-central-glowing-shield-symbol-180x128.webp",180,128,true],"genesis-singular-images":["https:\/\/www.codemotion.com\/magazine\/wp-content\/uploads\/2024\/12\/DALL\u00b7E-2024-12-09-14.08.18-A-horizontal-scene-depicting-the-concept-of-cybersecurity-in-a-visually-stunning-futuristic-style.-The-image-features-a-central-glowing-shield-symbol-896x504.webp",896,504,true],"archive-featured":["https:\/\/www.codemotion.com\/magazine\/wp-content\/uploads\/2024\/12\/DALL\u00b7E-2024-12-09-14.08.18-A-horizontal-scene-depicting-the-concept-of-cybersecurity-in-a-visually-stunning-futuristic-style.-The-image-features-a-central-glowing-shield-symbol-400x225.webp",400,225,true],"gb-block-post-grid-landscape":["https:\/\/www.codemotion.com\/magazine\/wp-content\/uploads\/2024\/12\/DALL\u00b7E-2024-12-09-14.08.18-A-horizontal-scene-depicting-the-concept-of-cybersecurity-in-a-visually-stunning-futuristic-style.-The-image-features-a-central-glowing-shield-symbol-600x400.webp",600,400,true],"gb-block-post-grid-square":["https:\/\/www.codemotion.com\/magazine\/wp-content\/uploads\/2024\/12\/DALL\u00b7E-2024-12-09-14.08.18-A-horizontal-scene-depicting-the-concept-of-cybersecurity-in-a-visually-stunning-futuristic-style.-The-image-features-a-central-glowing-shield-symbol-600x600.webp",600,600,true]},"uagb_author_info":{"display_name":"peduz91","author_link":"https:\/\/www.codemotion.com\/magazine\/author\/peduz91\/"},"uagb_comment_info":0,"uagb_excerpt":"La sicurezza del codice non \u00e8 un optional: \u00e8 una responsabilit\u00e0 essenziale di ogni sviluppatore. Questo articolo inaugura una serie dedicata a come scrivere codice sicuro, affrontando una delle minacce pi\u00f9 diffuse e pericolose nello sviluppo di applicazioni: le SQL Injection. Cos&#8217;\u00e8 una SQL Injection? La SQL Injection \u00e8 un attacco in cui un utente&#8230;&hellip;","lang":"it","_links":{"self":[{"href":"https:\/\/www.codemotion.com\/magazine\/wp-json\/wp\/v2\/posts\/30999","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.codemotion.com\/magazine\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.codemotion.com\/magazine\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.codemotion.com\/magazine\/wp-json\/wp\/v2\/users\/218"}],"replies":[{"embeddable":true,"href":"https:\/\/www.codemotion.com\/magazine\/wp-json\/wp\/v2\/comments?post=30999"}],"version-history":[{"count":3,"href":"https:\/\/www.codemotion.com\/magazine\/wp-json\/wp\/v2\/posts\/30999\/revisions"}],"predecessor-version":[{"id":31960,"href":"https:\/\/www.codemotion.com\/magazine\/wp-json\/wp\/v2\/posts\/30999\/revisions\/31960"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.codemotion.com\/magazine\/wp-json\/wp\/v2\/media\/31041"}],"wp:attachment":[{"href":"https:\/\/www.codemotion.com\/magazine\/wp-json\/wp\/v2\/media?parent=30999"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.codemotion.com\/magazine\/wp-json\/wp\/v2\/categories?post=30999"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.codemotion.com\/magazine\/wp-json\/wp\/v2\/tags?post=30999"},{"taxonomy":"collections","embeddable":true,"href":"https:\/\/www.codemotion.com\/magazine\/wp-json\/wp\/v2\/collections?post=30999"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}