The Last XSS Defense Talk: Why XSS Defense has radically changed in the past 7 years - Jim Manico

  Рет қаралды 677

OWASP Foundation

OWASP Foundation

Күн бұрын

OWASP AppSec EU 2018 Hacker Track - Day 1, talk 4
Why are we still talking about Cross Site Scripting in 2018? Because it's painfully difficult to defend against XSS even to this day. This talk is a fundamental update to the 2011 AppSec USA talk "The Past Present and Future of XSS Defense". We'll address new defensive strategies such as modern JavaScript framework defense in Angular, React and other frameworks. We'll also look at how CSP deployment has changed in the past 7 years illustrating the progressive use of content security which supports CSP v1, v2 and v3 concurrently. We will then look at advances in HTML sanitization on both the client and server and focus on sanitizers and defensive libraries that have stood the test of time in terms of maintenance and security. We'll also look at interesting design topics such as how HTML injection is still critical even in the face of rigorous XSS defense and how HTTPOnly cookies are largely ineffective. This talk should help developers and security professionals alike build a focused and modern strategy to defend against XSS in modern applications.
Managed by the official OWASP Media Project www.owasp.org/...

Пікірлер: 1
Think Fast, Talk Smart: Communication Techniques
58:20
Stanford Graduate School of Business
Рет қаралды 41 МЛН
Ouch.. 🤕⚽️
00:25
Celine Dept
Рет қаралды 17 МЛН
НАШЛА ДЕНЬГИ🙀@VERONIKAborsch
00:38
МишАня
Рет қаралды 2,8 МЛН
Synyptas 4 | Арамызда бір сатқын бар ! | 4 Bolim
17:24
Wolfram Physics Project Launch
3:50:19
Wolfram
Рет қаралды 1,8 МЛН
OWASP API Security Project - Paulo Silva & Erez Yalon
31:22
OWASP Foundation
Рет қаралды 1,1 М.
Simple Code, High Performance
2:50:14
Molly Rocket
Рет қаралды 255 М.
Ouch.. 🤕⚽️
00:25
Celine Dept
Рет қаралды 17 МЛН