Главная
Study mode:
on
1
- Stream Start
2
- Intro
3
- Understanding DevSecOps
4
- What are the problems in DevSecOps?
5
- How bad is the situation?
6
- Java Demo Application
7
- Snyk Plugin Alerting to Security Issues in Your Code
8
- Path Traversal Issue in Code
9
- Open Source and How Things Can Go Wrong
10
- Example of Open Source Problems in the Demo App
11
- What Your App Consists Of
12
- Open Source Usage Has Exploded
13
- Understanding Log4j Vulnerability
14
- Demo of Exploiting Log4j Vulnerability
15
- Java Serialization Issues
16
- I am root
17
- How Confident are Open Source Maintainners in Security
18
- Who is responsible for security?
19
- Next Layer of the Modern App Iceberg
20
- Vulnerabilities per Docker image
21
- Let's Hack Containers
22
- I am root again!
23
- Infrastructure as Code and what security concerns to consider
24
- What is the solution?
25
- Snyk Demo
26
- DevSecOps Recap
27
- Closing
Description:
Dive into a comprehensive live-hacking session focused on Java and cloud-native application security. Explore common threats, vulnerabilities, and misconfigurations in modern software development, from open-source dependencies to containerization and infrastructure as code. Learn about critical issues like path traversal, the Log4j vulnerability, and Docker image security. Discover actionable remediation strategies and best practices to protect your applications throughout the DevSecOps lifecycle. Gain insights into the expanding attack surface of Java applications and understand the shared responsibility of security in today's software-driven world.

Stranger Danger - Your Java Attack Surface Just Got Bigger

Snyk
Add to list
0:00 / 0:00