Главная
Study mode:
on
1
Cross-Site Scripting (XSS)
2
Contextual Output Encoding
3
Content Security Policy
4
CSP Requirements
5
CSP Directives
6
CSP Examples
7
Strict-Transport-Security
8
X-Frame-Options
9
Using Secure Headers
10
Cross-Site Request Forgery (CSRF)
11
OWASP 1-Liner
12
Normal JSON Message
13
CSRF Attack Form
14
Forged JSON Message
15
CSRF Defense
16
CSRFGuard JSP Tags
17
CSRFGuard DOM Manipulation
Description:
Explore modern web application defense techniques using OWASP tools in this 40-minute conference talk from AppSecUSA 2014. Dive into common vulnerabilities like Cross-Site Scripting (XSS), Session Hijacking, and Clickjacking, and learn how to mitigate them effectively. Witness live demonstrations of OWASP projects and tools in action, and discover proactive strategies to prevent attacks and protect applications. Gain insights into Contextual Output Encoding, Content Security Policy, Strict-Transport-Security, and Cross-Site Request Forgery (CSRF) defenses. Participate in an interactive session designed for developers and architects to enhance their understanding of practical security solutions and risk mitigation techniques.

Modern Web Application Defense with OWASP Tools

OWASP Foundation
Add to list
0:00 / 0:00