Things I need to know about security

Lightning talk given at the August RORO. Trying to give a basic overview of 3 security threats to your web application.


Jonathan Yeong

August 09, 2016


  2. SQL Injection Cross Site Scripting (XSS) Session Hijacking What and

  3. What Uses SQL as an input which will influence a

    database and cause the application to perform an unintended action. How Sanitize your inputs! SQL Injection Impact: Devastating Exploitability: Easy
  4. XKCD: Exploits of a mom. SQL Injection

  5. Cross Site Scripting (XSS) What A XSS attack occurs when

    malicious code is saved by the application and is then redisplayed without interference from security mechanisms. How Sanitize your outputs! Impact: Harmful Exploitability: Easy
  6. Cross Site Scripting (XSS)

  7. Session Hijacking Impact: Harmful Exploitability: Moderate What Session hijacking refers

    to the scenario where an attacker is able to impersonate a legitimate user, either by stealing their session identifier, or forging session information. [1] How Use HTTPS - enforce SSL for pages you don’t want a hacker to access. Set your cookies to secure and httponly.
  8. Thanks for listening! @jonoyeong What are some other important

    security things we should know about?
