Главная
Study mode:
on
1
Intro
2
What is this web
3
Browsers!
4
How can I see what a browser is doing?
5
Setting up your Browser Proxy.
6
What is a HTTP Request?
7
URL Structure
8
COOOKIES YOU SAY?
9
HTML Responses
10
Attacker Mentality
11
Who is your threat?
12
What do you want to get?
13
How will you get it?
14
Insufficient Authentication Tips
15
Insufficient Authorization
16
Authorization Tips & Tricks
17
Session Hi-Jacking (Session Fixation)
18
Cross Site Scripting (XSS)
19
XSS EXAMPLE
20
Common XSS Test Strings
21
XSS Analysis
22
What is SQL?
23
Common SQLi Uses
24
SQL Injection Workflow
25
Cross Site Request Forgery (CSRF)
26
CSRF Attack Scenario
27
Quick Bonuses
Description:
Explore application security fundamentals in this 43-minute DerbyCon conference talk. Dive into web browser mechanics, HTTP requests, and URL structures. Learn to set up browser proxies, understand cookies, and analyze HTML responses. Adopt an attacker's mindset by identifying threats and objectives. Discover tips for addressing insufficient authentication and authorization, and explore common vulnerabilities like session hijacking, cross-site scripting (XSS), SQL injection, and cross-site request forgery (CSRF). Gain practical insights with examples, test strings, and attack scenarios to enhance your web application security knowledge.

Appsec TLDR

Add to list
0:00 / 0:00