BSidesSF 2018 - No More XSS: Deploying CSP with nonces and strict-dynamic (Devin Lundberg)

  Рет қаралды 9,858

Security BSides San Francisco

Security BSides San Francisco

Күн бұрын

Пікірлер: 5
@TamObso
@TamObso 4 ай бұрын
Just learning about all this, so this was very VERY helpful in understanding the use of "strict-dynamic", "nonce", and using them in conjunction with one another.
@domaincontroller
@domaincontroller 3 жыл бұрын
03:35 Templates 04:09 auto-escaping doesn't always work, django, rails, safe, react 05:29 HTTP header read list who can access resources on your page 06:11 pinterest, CSP script-src, whitelist 07:14 others directive 07:24 object-src
@timelord404
@timelord404 3 жыл бұрын
thanks man
@rajani123yt
@rajani123yt 3 жыл бұрын
Thanks for nice explanation on CSP and nonce concepts
@hazhohuman
@hazhohuman 2 жыл бұрын
please put the resources in the description
Don't look down on anyone#devil  #lilith  #funny  #shorts
00:12
Devil Lilith
Рет қаралды 45 МЛН
My Daughter's Dumplings Are Filled With Coins #funny #cute #comedy
00:18
Funny daughter's daily life
Рет қаралды 29 МЛН
Это было очень близко...
00:10
Аришнев
Рет қаралды 1,1 МЛН
Browser security with HTTP headers - David Lord
33:42
SF Python
Рет қаралды 5 М.
Angular Security with CSP: Interview with Dr phillipe de Ryck
23:54
Cross-Site Request Forgery (CSRF) Explained
14:11
PwnFunction
Рет қаралды 454 М.
Content-Security-Policy: An Introduction
30:28
Abhay Bhargav
Рет қаралды 42 М.
Content Security Policy
33:51
InfoQ
Рет қаралды 22 М.
Understanding CSP, the video tutorial edition
42:19
Troy Hunt
Рет қаралды 8 М.
HTTP Security Headers | Part 01
11:30
CyberSecurityTV
Рет қаралды 18 М.
Don't look down on anyone#devil  #lilith  #funny  #shorts
00:12
Devil Lilith
Рет қаралды 45 МЛН