Главная
Study mode:
on
1
Intro
2
Web Platform Bugs
3
Google CSP
4
Ghostbase CSP
5
Level 1 CSP
6
Advanced CSP
7
Refactoring
8
Strict Dynamic
9
Trusted Types
10
CSP Coverage
11
Guru Section
12
CSP
13
Nonce Only
14
Example
15
CSS
16
CSP Reporting
17
CSP Detection
18
Trick Dynamic
19
Conclusion
20
CSP evaluator
21
Questions
22
Browser Cache
23
SSRI
Description:
Explore the intricacies of Content Security Policy (CSP) and its role in combating XSS vulnerabilities in this in-depth talk from the Hack In The Box Security Conference. Delve into the technical analysis of various CSP flavors and their effectiveness against different classes of XSS vulnerabilities, debunking common myths and misconceptions. Gain insights into the blurred lines between hardening and mitigation techniques, and understand how CSP can provide robust defense-in-depth guarantees while enforcing best coding practices. Learn advanced CSP techniques and examine real-world data on how CSP has prevented XSS exploitation in sensitive applications on modern browsers. Discover the strengths, limitations, and complexity of CSP, covering topics such as nonce-based CSP, Ghostbase CSP, Strict Dynamic, Trusted Types, CSP Coverage, reporting, and detection. Equip yourself with practical knowledge on implementing and evaluating CSP, including examples, tricks, and tools like the CSP evaluator. Read more

A Successful Mess Between Hardening and Mitigation

Hack In The Box Security Conference
Add to list
00:00
-03:12