Главная
Study mode:
on
1
Intro
2
Sabre
3
About Dave
4
AppSec Mission
5
Complications
6
General Thoughts
7
Burp
8
Quick Wins
9
Finding Attack Surfaces
10
SSL Configuration
11
Sequel Injection
12
Crosssite Scripting
13
HTTP Response Headers
14
Engage Developers
15
AppSec maturity model
16
Alternatives
Description:
Discover practical strategies for enhancing application security in this 37-minute conference talk from LASCON 2014. Learn how to prioritize and implement quick wins to improve your software's security posture with limited resources. Explore various approaches including manual penetration testing, source code review, automated scanning, web application firewalls, threat modeling, and developer training. Gain insights on working effectively with development teams for remediation efforts. Understand how to measure progress and demonstrate improvement using a popular software security maturity model. Walk away with specific, actionable steps to strengthen your applications' security and raise the bar for potential attackers.

Practical AppSec - Quick Wins for More Secure Software

LASCON
Add to list
0:00 / 0:00