Главная
Study mode:
on
1
Introduction
2
What makes JavaScript great
3
MS Vulnerability
4
Regular Expressions
5
The Event Loop
6
Catastrophic Backtracking
7
Redose
8
Attack Manipulation
9
JSON as Input
10
Type Manipulation
11
DustJS
12
About Page
13
Playing with About Page
14
Wrapping Up
15
Takeaways
16
Libraries have bugs
17
Microsoft Sonar and Lighthouse
18
Upgrade
Description:
Learn essential techniques for writing secure JavaScript code in this 32-minute conference talk from View Source 2017. Explore the strengths of JavaScript, understand common vulnerabilities, and dive into topics such as regular expressions, the event loop, and catastrophic backtracking. Discover how to prevent attacks through input manipulation, JSON handling, and type manipulation. Examine real-world examples, including the DustJS vulnerability, and gain practical insights on securing web applications. Conclude with key takeaways on library vulnerabilities, utilizing tools like Microsoft Sonar and Lighthouse, and the importance of regular upgrades for maintaining code security.

Writing Secure JavaScript Code - Avoiding Vulnerabilities and Attacks

Mozilla Hacks
Add to list
0:00 / 0:00