Главная
Study mode:
on
1
Introduction
2
Agenda
3
Crosssite scripting
4
Templates and autoescape
5
No crosssite scripting
6
Content security policy
7
Domain whitelist
8
Object source base URI
9
HTML injection
10
Inline scripts
11
CSP nonces
12
What can go wrong
13
Hashes
14
Whitelisting
15
Strictdynamic
16
JavaScript templates
17
Deploying CSP
18
Easier to deploy
19
Code changes
20
Nonces
21
Change templates
22
Report only mode
23
CSP policy
24
Resources
25
Questions
26
Report URL
Description:
Explore a comprehensive conference talk on implementing Content Security Policy (CSP) to prevent cross-site scripting (XSS) vulnerabilities. Learn about the evolution of CSP, focusing on version 3's strict-dynamic mechanism, which simplifies application to existing web pages without major refactoring. Discover how Pinterest and Instapaper successfully deployed strict CSP, including implementation tips and potential pitfalls. Gain insights into topics such as nonces, hashes, whitelisting, and JavaScript templates. Understand the deployment process, necessary code changes, and the benefits of report-only mode. Equip yourself with practical knowledge to enhance web application security and effectively combat XSS attacks.

No More XSS - Deploying CSP with Nonces and Strict-Dynamic

Security BSides San Francisco
Add to list
0:00 / 0:00