Better WordPress Security with WordPress Nonces | WordPress PHP Security

  Рет қаралды 8,953

WPCasts

WPCasts

Күн бұрын

Пікірлер: 30
@WPCasts
@WPCasts 4 жыл бұрын
Let's chat on Twitter! twitter.com/AlexanderBYoung
@jlcdrivewayramps7343
@jlcdrivewayramps7343 Жыл бұрын
simple. clear. I cant stand tutorials which are too complex. they confuse more than help. keep it simple and you did. thank you.
@patrickcameron2950
@patrickcameron2950 4 жыл бұрын
I'm a lot closer to wrapping my head around nonces than I was before - thank you! Looking forward to digging through your other videos.
@RyanDewhurst
@RyanDewhurst 4 жыл бұрын
Hey! Ryan here from WPScan. Great video. Just something to note that wasn't mentioned is that Chrome and other browsers will soon be enabling "SameSite=Lax" cookies by default, which will prevent most CSRF attacks in modern web browsers, when they implement it by default. Nonces should absolutely still be used of course, but the risk of a CSRF attack should also be reduced when web browsers implement SameSite by default.
@LevyCarneiro
@LevyCarneiro 4 жыл бұрын
Great format with you facing diagonally. Best format I've seen for screencast videos.
@manavbudhia
@manavbudhia 4 жыл бұрын
Great to see your video after long time..
@wassy83
@wassy83 4 жыл бұрын
Thank you so much!
@Pharoxx105
@Pharoxx105 4 жыл бұрын
Could you explain how to use a nonce with cached form pages? I want to serve the form page from a static cache
@patrickcameron2950
@patrickcameron2950 4 жыл бұрын
Perhaps best to just exclude that page from caching?
@leebuckle8288
@leebuckle8288 4 жыл бұрын
People in the UK reading the title like -.-
@MoserDamasceno
@MoserDamasceno 4 жыл бұрын
Thank you!
@rauljauregi6615
@rauljauregi6615 4 жыл бұрын
nice! Thank you very much
@gorangagrawal
@gorangagrawal 2 жыл бұрын
How to get NOnce for Headless WordPress? Custom endpoint i.e with REST API? And if yes then should we secure the Nonce endpoint by checking like current_user_can() or should just let it be without any checks?
@amitbiswas1885
@amitbiswas1885 4 жыл бұрын
What happens if user open this form as not logged in state and then login in another tab, return to first tab and submit the form? Nonce error happens. Why? how to deal with that situation?
@TheMarouuu
@TheMarouuu 4 жыл бұрын
Great stuff!
@Zak_Nike
@Zak_Nike 14 күн бұрын
No nonce jokes😮 I'm obviously in the wrong place
@vladtircomnicu1630
@vladtircomnicu1630 4 жыл бұрын
Super useful
@alex_ishchenko
@alex_ishchenko 4 жыл бұрын
Thanks!
@afflictionmarketing5303
@afflictionmarketing5303 4 жыл бұрын
I don't understand it. Because the nonce filed is a hidden field. Evey when bot submit the request still isset return true and query get executed. ????
@АлександрГригорий-е6о
@АлександрГригорий-е6о 4 жыл бұрын
Note that the nonces are unique to the current user's session, so if a user logs in or out asynchronously any nonces on the page will no longer be valid. codex.wordpress.org/WordPress_Nonces
@Draanor
@Draanor 4 жыл бұрын
Nonces are to stop replay attacks, they are to help ensuring that a request was made from a valid source and that the request is only run only once and that the primed request can expire if the user fails to submit. Nonces are basically useless on forms that don't require user authentication.
@АлександрГригорий-е6о
@АлександрГригорий-е6о 4 жыл бұрын
Hello, what are you using for bundling JS?
@WPCasts
@WPCasts 4 жыл бұрын
I actually wasn't bundling it. I was just using the browser-supported ES6 :)
@msvmanikantasrivishnu7788
@msvmanikantasrivishnu7788 4 жыл бұрын
1st like :-)
@WPCasts
@WPCasts 4 жыл бұрын
🎉 woot!
@ReLLaKaT316
@ReLLaKaT316 4 жыл бұрын
Noooonce
@AndrewRhyand
@AndrewRhyand 4 жыл бұрын
Always love how you dig deeper into WP more than the average channel! Check out the function check_ajax_referer() (developer.wordpress.org/reference/functions/check_ajax_referer/). It pretty much does what you built, but with a simple function call. It's super handy.
@muhammadfarooqi
@muhammadfarooqi 3 жыл бұрын
it's not useful.... it is very useful....:) thankx
@WPCasts
@WPCasts 3 жыл бұрын
Glad to hear that!
3 Methods for AJAX in WordPress | Which Method is the Best?
23:09
Как Ходили родители в ШКОЛУ!
0:49
Family Box
Рет қаралды 2,3 МЛН
I'VE MADE A CUTE FLYING LOLLIPOP FOR MY KID #SHORTS
0:48
A Plus School
Рет қаралды 20 МЛН
Почему Катар богатый? #shorts
0:45
Послезавтра
Рет қаралды 2 МЛН
Every team from the Bracket Buster! Who ya got? 😏
0:53
FailArmy Shorts
Рет қаралды 13 МЛН
I now use Solid Security for my WordPress websites
25:53
Rino de Boer
Рет қаралды 14 М.
BSidesSF 2018 - No More XSS: Deploying CSP with nonces and strict-dynamic (Devin Lundberg)
29:24
Make Your WordPress Site More Secure with PHP dotenv
9:18
How To Create Dynamic Routes In WordPress
16:15
WPCasts
Рет қаралды 18 М.
10 Easy Ways to Make Your WordPress Site Secure
4:34
Tony Teaches Tech
Рет қаралды 6 М.
The Ultimate WordPress Security Guide To Prevent Hacking & Malware Attacks
31:27
WPCrafter.com WordPress For Non-Techies
Рет қаралды 51 М.
How To Make a WordPress Website 2025 - Step by Step
1:33:45
Metics Media
Рет қаралды 208 М.
OAuth 2.0 and OpenID Connect (in plain English)
1:02:17
OktaDev
Рет қаралды 1,8 МЛН
Как Ходили родители в ШКОЛУ!
0:49
Family Box
Рет қаралды 2,3 МЛН