DjangoCon Europe 2023 | A Beginners Guide to Security Exploits in Action

  Рет қаралды 1,088

DjangoCon Europe

DjangoCon Europe

Күн бұрын

A Beginners Guide to Security Exploits in Action
by Ashley Mathew & Mario de la Ossa
pretalx.com/dj...
It’s one thing to read the Django security page and follow the recommendations. It’s something completely different to actually understand why those recommendations exist.
The talk will cover 5 different security vulnerabilities (spending ~5 mins on each) that are baked into a fake MySpace clone:
HTML serialization: Why supporting custom HTML is cool, but also dangerous
The penalties of using a guessable SECRET_KEY: How one might use it to abuse sessions
The downfalls of stepping outside the ORM: How write a more complex query and accidentally make it vulnerable to SQL injection
Consider setting ALLOWED_HOSTS: Injecting custom hosts in password reset emails
No really, consider setting ALLOWED_HOSTS: Unsafe open redirects and the importance of url_has_allowed_host_and_scheme
Each step will introduce in detail how to exploit the vulnerability, followed by patching and validation.

Пікірлер
DjangoCon Europe 2023 | The programmer's imagination
53:05
DjangoCon Europe
Рет қаралды 604
Арыстанның айқасы, Тәуіржанның шайқасы!
25:51
QosLike / ҚосЛайк / Косылайық
Рет қаралды 700 М.
Quando eu quero Sushi (sem desperdiçar) 🍣
00:26
Los Wagners
Рет қаралды 15 МЛН
How to treat Acne💉
00:31
ISSEI / いっせい
Рет қаралды 108 МЛН
Microservices with Databases can be challenging...
20:52
Software Developer Diaries
Рет қаралды 111 М.
An Illustrated Guide to OAuth and OpenID Connect
16:36
OktaDev
Рет қаралды 623 М.
Free local AI Server at Home: Step-by-Step Guide
14:24
Lepczynski Tech Cloud Adventures
Рет қаралды 7 М.
SQL Injection | Complete Guide
1:11:53
Rana Khalil
Рет қаралды 263 М.
Making A Billion-Year Lego Clock
13:11
Brick Technology
Рет қаралды 8 МЛН
2024's Biggest Breakthroughs in Math
15:13
Quanta Magazine
Рет қаралды 405 М.
Why Agent Frameworks Will Fail (and what to use instead)
19:21
Dave Ebbelaar
Рет қаралды 101 М.
What are you going to do in 2023? Tops 5 skills to get!
18:56
David Bombal
Рет қаралды 2,4 МЛН
Solving one of PostgreSQL's biggest weaknesses.
17:12
Dreams of Code
Рет қаралды 219 М.