Главная
Study mode:
on
1
Introduction
2
Introducing Oliver Lavery
3
The fundamental problem
4
How to escape data
5
Strict structural validation
6
The root cause of vulnerability
7
We blame the developers
8
We blame the technologies
9
WAAFs fall short
10
What is the solution
11
Framework security
12
Fixing the foundation
13
Self defending frameworks
14
Isapi
15
No code changes
16
Application
17
XSS
18
Examples
19
Contextaware escaping
20
Challenges
21
Demo
22
Example
23
Edge Cases
24
HTML
25
Sequel
26
Objection
27
Coordinate State
28
Writing Good Software
29
Performance Impact
30
XSS Protection
31
Authentication
32
Crosssite scripting
Description:
Explore framework security and developer-friendly approaches to application security in this AppSecEU 2016 conference talk. Delve into the fundamental problems of data escaping and structural validation, examining the root causes of vulnerabilities. Challenge common misconceptions about blame attribution and evaluate the limitations of Web Application Firewalls. Discover the concept of self-defending frameworks and their potential to revolutionize security without code changes. Learn about context-aware escaping, edge cases, and performance considerations. Gain insights into XSS protection, authentication, and cross-site scripting through practical examples and demonstrations.

Framework Security: Hugging Developers Through Self-Defending Systems - AppSecEU 2016

OWASP Foundation
Add to list