Главная
Study mode:
on
1
Intro
2
Agenda
3
JavaScript History
4
JavaScript vs JScript
5
Syntax Extensions
6
Standardization
7
ECMA Script 6
8
Arrow Functions
9
Generator Functions
10
Bypassing the Sandbox
11
Generator Arrows
12
Escapes
13
Templating Strings
14
Multiline strings
15
IE XSS filter
16
Location filter
17
Shape Layer
18
Symbols
19
Unique immutable reference
20
Symbol to string tag
21
Serialization of string tags
22
Unstoppable
23
Use Includes
24
Reflection
25
Mixed Salad
26
Conclusion
Description:
Explore the world of ECMAScript 6 from a security perspective in this 57-minute conference talk from nullcon Goa 2015. Delve into the development, implementation, and implications of ES6 for web security. Gain insights into new code constructs, attack vectors, and mitigation strategies. Unravel complex terminology like expression interpolation, proper tail calls, computed properties, spread parameters, modules, and tagged template strings. Learn about JavaScript history, syntax extensions, standardization, and new features such as arrow functions and generator functions. Discover how ES6 can be used to bypass sandboxes, exploit templating strings, and leverage symbols. Examine security concerns related to reflection and mixed content. Leave with a comprehensive understanding of ECMAScript 6's impact on web security and how to address potential vulnerabilities.

ECMA Script 6 from an Attacker's Perspective

nullcon
Add to list
0:00 / 0:00