Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
Beyond Scanning
Search
Dheeraj Joshi
November 15, 2016
Technology
500
0
Share
Embed
Copy iframe code
Copy JS code
Copy link
Start on current slide
Beyond Scanning
Slides from my talk at SeleniumConf UK 2016!
Dheeraj Joshi
November 15, 2016
More Decks by Dheeraj Joshi
See All by Dheeraj Joshi
Secure your Web Application
djadmin
0
6.7k
Let's talk Security
djadmin
0
7.7k
Other Decks in Technology
See All in Technology
OpenTelemetryにおけるGoのゼロコード・コンパイル時計装について #fukuokago
quiver
0
330
AIエージェントがあれば技術書なんてすぐ書けるでしょ→無理でした
watany
4
480
文字起こし基盤の信頼性
abnoumaru
0
140
AI時代こそ、スケールしないことをしよう -「作る人」から「なぜ作るか」を考える人へ / Do Things That Don't Scale in the AI Era — From How to Why
kaminashi
1
150
『モデル + ハーネス』で読み解く AIエージェント入門
oracle4engineer
PRO
2
200
現場との対話から始める “作る前に問い直す”業務改善
mochico50
2
310
どこまでAIに任せるか 〜確率論と決定論の境界決定〜
shukob
0
520
CloudWatchから始めるAWS監視
butadora
0
180
モバイル研修【MIXI 26新卒技術研修】
mixi_engineers
PRO
1
170
Jitera Company Deck
jitera
0
570
AI研修(Day1)【MIXI 26新卒技術研修】
mixi_engineers
PRO
1
1.2k
発表と総括 / Presentations and Summary
ks91
PRO
0
210
Featured
See All Featured
How to Get Subject Matter Experts Bought In and Actively Contributing to SEO & PR Initiatives.
livdayseo
0
160
Google's AI Overviews - The New Search
badams
0
1.1k
10 Git Anti Patterns You Should be Aware of
lemiorhan
PRO
659
62k
Designing for Timeless Needs
cassininazir
1
400
What’s in a name? Adding method to the madness
productmarketing
PRO
24
4.1k
Agile Leadership in an Agile Organization
kimpetersen
PRO
0
190
A brief & incomplete history of UX Design for the World Wide Web: 1989–2019
jct
2
430
Lightning talk: Run Django tests with GitHub Actions
sabderemane
0
220
Navigating the moral maze — ethical principles for Al-driven product design
skipperchong
2
420
The Illustrated Children's Guide to Kubernetes
chrisshort
51
53k
Helping Users Find Their Own Way: Creating Modern Search Experiences
danielanewman
31
3.3k
Save Time (by Creating Custom Rails Generators)
garrettdimon
PRO
32
3.9k
Transcript
Let’s talk Security Beyond Scanning Dheeraj Joshi @dheerajhere
• Front-End @ • Previously @ • Open Source (medium-cli)
• Ambidextrous TT Player About Me
More... Uber, CKEditor, Dropbox, MailChimp, Recruiterbox, InVision, DigitalOcean, Intuit, Groupon,
etc. What makes me happy?
In this talk... • Why ? • Cross-site Scripting (XSS)
• Cross-site Request Forgery (CSRF) • Content Security Policy (CSP) • HTTP Security Headers • Best Practices & Demo
Why should we Care about Security? Startups & SMEs are
known to cut corners. One of the first things they cut is ‘Security'.
None
None
None
Password Reuse Attacks
HACKER PUTS HOSTING SERVICE “CODE SPACES” OUT OF BUSINESS The
Shutdown
CROSS SITE SCRIPTING - XSS • XSS attack users •
Inject Malicious content • Exploits can be real bad
What is XSS? Typical Reflected XSS
Stored XSS
DOM XSS
Hunt... • Data <-> Code • Input Validation • Check
HTML Encoding • Sanitizers • Analyze places where DOM elements are created
XSS via template injection Using Sandbox Bypasses http://blog.portswigger.net/2016/04/adapting-angularjs -payloads-to-exploit.html
• Check for HTTPOnly, Secure flag on Session Cookie
CROSS-SITE REQUEST FORGERY (CSRF)
Because the attack is carried out by the victim, CSRF
can bypass: • HTTP Auth • Session-based auth • Firewalls CSRF Attacks
• Only accepting POST requests • Referer Protection • Multi-Step
Transactions • URL Rewriting • application/json “CSRF Myths” Preventions that Won’t work
XSS + CSRF = ?
Content Security Policy (CSP) CSP Evaluator (https://csp-evaluator.withgoogle.com)
HTTP Security headers • Strict-Transport-Security: max-age=16070400; includeSubDomains • X-Frame-Options: deny
• X-XSS-Protection: 1; mode=block • X-Content-Type-Options: nosniff
Defense • Strategy - Integrate into SDLC • Static Code
Analysis • Security Audits • CTFs
Show Time !
Questions ?
Thank you @dheerajhere @djadmin