Главная
Study mode:
on
1
Intro
2
Jason Gillam
3
Kevin Johnson
4
Web Applications Have Changed...
5
So has development...
6
We need to adapt!
7
HTTP/2 is a Big Upgrade
8
Testing HTTP/2
9
Testing Websockets
10
What's an "Origin"?
11
SOP Exceptions
12
Fetching a CORS Policy
13
CORS Pentest Considerations
14
Focus on the Client
15
REST Clients
16
Testing Considerations
17
Content Security Policy (CSP)
18
CSP Versions
19
Browser Support
20
Main Differences in 4.0
Description:
Explore next-generation web penetration testing techniques for modern applications in this 58-minute conference talk from AppSecUSA 2016. Discover how to adapt testing methods to handle new technologies like HTTP/2, WebSockets, CORS, RESTful APIs, and Content Security Policy (CSP). Learn about the nuances of these advancements and their impact on security testing from industry experts Kevin Johnson and Jason Gillam. Gain insights into testing considerations for each technology, including client-side focus and browser support. Understand the evolution of web applications and development practices, and how penetration testing must evolve to keep pace. Conclude with an introduction to the new modern vulnerable application and the release of SamuraiWTF 4.0, providing practical tools for implementing these advanced testing techniques.

Next Gen Web Pen Testing - Handling Modern Applications in a Penetration Test

OWASP Foundation
Add to list
0:00 / 0:00