Главная
Study mode:
on
1
Intro
2
Software developers
3
Whos vulnerable
4
White Hat
5
Windows Exposure
6
Challenges to Secure Applications
7
Market Forces
8
Knowledge Gap
9
Constraints
10
Security maturity models
11
Crash tests
12
Software and security
13
Raise awareness and education
14
Prioritize
15
Top 10
16
Injection
17
Taxonomy
18
Types of XSS
19
Reflected Example
20
Context Matters
21
Injection Points
22
JavaScript
23
Crosssite scripting vulnerabilities
24
Twitter scripting vulnerabilities
25
Browser protection
26
Crosssite scripting
27
Takeaways
28
Injection Mitigation
29
Encoding
30
AntiXSS
31
Whitelisting
32
Unicode
33
Context
34
ModelController
35
Demo
36
Metasploit
37
Aurora
38
Screenshot
39
Takeaway
Description:
Learn about defending against cross-site scripting (XSS) attacks in this 59-minute conference talk by Jason Montgomery. Explore the challenges faced by software developers in securing applications, including market forces and knowledge gaps. Understand different types of XSS attacks, injection points, and vulnerabilities through real-world examples like Twitter. Discover practical mitigation strategies such as encoding, whitelisting, and using Anti-XSS libraries. Gain insights into browser protection mechanisms and security maturity models. Watch a demonstration using Metasploit and Aurora, and leave with actionable takeaways to improve your application's security against XSS threats.

Defending Against Cross-Site Scripting (XSS) Vulnerabilities

Add to list
0:00 / 0:00