Главная
Study mode:
on
1
Intro
2
Main XSS variants
3
Web security model: Same Origin Policy, 1995
4
Juicy targets: Electron apps
5
Most common bypasses
6
Disable JavaScript
7
Trusted Types
8
Cookies security
9
The future of browser defenses
10
Server Side Rendering options
11
Auto Content Security Policy for Server Side Rendering
12
Templating engines-level mitigations
13
Static Application Security Testing (SAST)
14
Existing standards mitigations overview (aka security headers soupe)
15
The future of server side mitigations
16
Battlecards: XSS threat model
17
Frameworks and associated risks
18
Supply chain security: XSS specific risks Remote dependencies can be tampered with
19
XSS defense in depth
Description:
Explore the complexities of XSS attacks and mitigations in this comprehensive conference talk from BSidesSF 2022. Delve into essential topics such as CSPv3, Trusted Types, Strict Dynamic, CORP, and CORB to implement effective XSS defenses across multiple layers. Learn about the evolution of web security models, common bypass techniques, and specific vulnerabilities in Electron apps. Discover server-side rendering options, auto Content Security Policy implementation, and templating engine-level mitigations. Examine the role of Static Application Security Testing (SAST) and existing standard mitigations through security headers. Gain insights into the future of browser and server-side defenses, and understand XSS-specific risks in supply chain security. This talk equips you with the knowledge to create a robust, multi-layered approach to XSS mitigation in modern web applications.

XSS Mitigation - The State of the Art

Security BSides San Francisco
Add to list
0:00 / 0:00