Главная
Study mode:
on
1
Intro
2
Client security
3
Traditional XSS in JS code: execution sinks
4
The times have changed
5
Lightning-fast Introduction to Angular
6
Mixing Angular and server-side templates
7
Modifying the Angular DOM
8
Forcing evil ng-includes
9
$http.jsonp() on evil URL
10
XSS #5.2: Scary jQlite functions: html() & friends
11
Angular "special" functions
12
Opting into dangerous modes
Description:
Explore the security challenges and vulnerabilities in modern JavaScript frameworks in this JSConf EU 2015 talk by Artur Janc. Gain insights into common pitfalls affecting code written using popular frameworks like Angular, Polymer, and Dart. Learn about real-world examples of bugs in Google apps from a security engineer's perspective. Understand why security reviews of framework-based applications can be more challenging than traditional JavaScript code. Discover the importance of framework design in addressing security concerns. Topics covered include traditional XSS in JS code, mixing Angular with server-side templates, modifying the Angular DOM, dangerous jQuery-like functions, and opting into risky modes. Enhance your understanding of web application security in the context of modern JavaScript development.

Security in the World of JS Frameworks

JSConf
Add to list