Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Sign up for free
Menu
Search
Features
All features
Private URLs
Password Protection
Custom URLS
Scheduled publishing
Remove Branding
Restrict embedding
Deck Collections
Notes
Features
All features
Private URLs
Password Protection
Custom URLS
Scheduled publishing
Remove Branding
Restrict embedding
Deck Collections
Notes
Explore
Featured decks
Featured speakers
Programming
Technology
Storyboards
Explore
Featured decks
Featured speakers
Programming
Technology
Storyboards
Pricing
Search
Sign in
Sign up for free
Deep Dive into Application Security For Rails E...
Search
Sponsored
·
SiteGround - Reliable hosting with speed, security, and support you can count on.
→
zassmin
May 01, 2019
Technology
270
0
Share
Embed
Copy iframe code
Copy JS code
Copy link
Start on current slide
Deep Dive into Application Security For Rails Engineers
zassmin
May 01, 2019
Other Decks in Technology
See All in Technology
20260930_Gemma4_Hands-on
tsho
0
210
Argo CDとAtlantisで実現するインフラ管理のセルフサービス化──小規模SREチームで支えるプラットフォーム
cassius7
0
280
Oracle Base Database Service 技術詳細
oracle4engineer
PRO
16
120k
個別開発で終わらせない。 現場の課題をプロダクトの強さに変える StockmarkのFDE
ktkrhr
0
550
サーバーフルコンピューティング?AWS Lambda
iwatatomoya
0
140
Meet AgentCore Identity Consent Portal
hironobuiga
3
170
AI Made Us Faster at Solving the Wrong Problems
marceloancelmo
0
150
高負荷プロダクション環境におけるAWS Lambdaのリアル 〜スケールとコストを左右する実行ライフサイクルの技術仕様〜
maimyyym
2
850
2026-09-26 Platform Engineering Kaigi 2026 インフラとアプリの境界線と委譲の設計 / Drawing the Infra and App Line
masasuzu
0
600
[2026-09-30]ロックンロールは鳴り止まないっ - 信頼性かまってちゃん - 「データ駆動を投げ捨ててまで。」追いかける信頼性改善に向けた取り組みの話
tosite
0
190
spanner-autoscalerに学ぶ CRD設計パターン 〜自動化と緊急時対応を両立する Kubernetesコントローラーの作り方〜
tkuchiki
0
230
1万名の社員が使う認証基盤で どう信頼性を担保するか?
kairim0
0
180
Featured
See All Featured
Claude Code のすすめ
schroneko
67
230k
Large-scale JavaScript Application Architecture
addyosmani
515
110k
ラッコキーワード サービス紹介資料
rakko
1
5.1M
Building AI with AI
inesmontani
PRO
1
1.3k
コードの90%をAIが書く世界で何が待っているのか / What awaits us in a world where 90% of the code is written by AI
rkaga
63
46k
The #1 spot is gone: here's how to win anyway
tamaranovitovic
4
1.2k
Building Applications with DynamoDB
mza
96
7.2k
Intergalactic Javascript Robots from Outer Space
tanoku
273
27k
Abbi's Birthday
coloredviolet
4
10k
Everyday Curiosity
cassininazir
0
340
Self-Hosted WebAssembly Runtime for Runtime-Neutral Checkpoint/Restore in Edge–Cloud Continuum
chikuwait
0
850
Practical Tips for Bootstrapping Information Extraction Pipelines
honnibal
25
2.1k
Transcript
Deep Dive into Application Security
CONFIDENTIAL About Me • Application Security Engineer at Coinbase ◦
Focus: coinbase.com • A little on Coinbase
CONFIDENTIAL Talk Overview 1. Application Security Overview 2. Security Reviewing
an Application a. Application + Feature Set b. What can go wrong? c. 5 Security Principles d. Fixing the Problems 3. Recap
Application Security
Helps with defining services that operate safely so bad things
don’t happen to them.
Prevent and detect any action used in an unauthorized manner.
“A substantial dose of patience, creativity, and real technical expertise.”
- Michal Zalewski, The Tangled Web
Security Reviewing an Application
What Application will we review?
Built With • Backend: ◦ Rails ◦ Activerecord ◦ APIs
(3rd party) • Frontend: ◦ Bootstrap (3rd party) ◦ Javascript
None
Winter Exchange Daenerys Account Winter Exchange winterexchange.com Buy DGC Buy
DGC Send DGC Send DGC Send to: 34dig85
Dragon Glass Coin (DGC)
What are we working on? Server Winter Exchange
What are we working on? Server Winter Exchange Browser Daenerys’s
Session GET/POST/PUT/DELETE Establish User Session GET Account Info POST Buy POST Send
What are we working on? Server Winter Exchange POST Buy
POST Send DGC API Bank API
Server Winter Exchange Browser Daenerys’s Session GET/POST/PUT/DELETE Establish User Session
GET Account Info POST Buy POST Send POST Buy POST Send DGC API Bank API What are we working on?
Winter Exchange’s Feature Set • A platform to buy and
send Dragon Glass Coin (DGC) • Holds the users’ DGC • User can send DGC to anyone with an address • Stores users’ Data • User can buy DGC with USD
What can go wrong? - Adam Shostack
GET Account Info GET/POST/PUT/DELETE Establish User Session Server Winter Exchange
Browser Daenerys’s Session POST Buy POST Send POST Buy POST Send DGC API Bank API Trust Boundaries
1. Don’t Trust the Client - OWASP, Security By Design
Principles
GET Account Info GET/POST/PUT/DELETE Establish User Session Server Winter Exchange
Browser Daenerys’s Session POST Buy POST Send POST Buy POST Send DGC API Bank API Trust Boundaries
Could the Session be Stolen?
Possible Steps to Steal this Session 1. Find a cross
site scripting (XSS) vulnerability 2. Write quick html/javascript 3. Phish the user somehow to use the html/javascript 4. Steal cookie
Do We have a XSS on Winter Exchange? https://github.com/coinbase/salus
2. Don’t Trust Services 3rd Parties - OWASP, Security By
Design Principles
What can we do with a stolen session?
GET Account Info GET/POST/PUT/DELETE Establish User Session Server Winter Exchange
Browser Daenerys’s Session POST Buy POST Send POST Buy POST Send DGC API Bank API Trust Boundaries
Winter Exchange Where is Daenerys’s DGC going? Daenerys’s Account Unknown
Address
Fixing the Problems 1. Leaked the Session 2. Cross Site
Scripting Vulnerability in Bootstrap 3. Taking Daenerys’ DGC out of Winter Exchange
https://github.com/twitter/secure_headers
Vulnerability Scanner https://github.com/rubysec/bundler-audit https://github.com/presidentbeef/brakeman https://github.com/coinbase/salus
Patch Your Vulnerabilities
Second Factor Authentication
3. Defense in Depth Secure by Default - OWASP, Security
By Design Principles
GET Account Info GET/POST/PUT/DELETE Establish User Session Server Winter Exchange
Browser Daenerys’s Session POST Buy POST Send POST Buy POST Send DGC API Bank API Trust Boundaries
4. Least Privilege - OWASP, Security By Design Principles
What if Daenerys can get someone else’s account information? Daenerys
Account Winter Exchange winterexchange.com/user/3 • Aegon Targaryen • Personal Address: ◦ Tower of Joy • Drivers License • DGC Address
Daenerys Gets Any User’s Account Information
Fixing the Problems 1. Authorization 2. Insecure Direct Object Reference
3. Access to another User’s Account Information a. Leaking Information
Current User in Controller
Pundit https://github.com/varvet/pundit
Write Tests
UUID 1. 32 hexadecimal (base 16) digits, plus hyphens 2.
f81d4fae-7dec-11d0-a765-00a0c91e6bf6 3. One way hashing, deterministically generated
Privacy • Data Classification Policy ◦ Public, Internal, Confidential •
Redacting sensitive information
GET Account Info GET/POST/PUT/DELETE Establish User Session Server Winter Exchange
Browser Daenerys’s Session POST Buy POST Send POST Buy POST Send DGC API Bank API Trust Boundaries
5. Fail Securely Explicitly - OWASP, Security By Design Principles
How did Daenerys get 3 Dragons? Daenerys’s Active Session Buying
DGC $100 Process Buy Error Processing Payment Processes Error as Successful request Server Winter Exchange Bank API
Where’s the problem?
A Closer Look at #process_payment
Fixing the Problem 1. Truthy Value 2. Taking Daenerys’ DGC
out of Winter Exchange
Explicit Error Handling
Explicit Error Handling
Explicit Error Handling
Recap
“A substantial dose of patience, creativity, and real technical expertise.”
- Michal Zalewski, The Tangled Web
Questions as your guide: What are we working on? What
can go wrong? - Adam Shostack
There are many solutions to a problem!
Prevention Focused Solutions 1. Restrict cookie flags 2. Sanitize html
3. Patch 3rd party libraries 4. Write tests 5. Have second factor auth 6. Data confidentiality plan 7. UUIDs
Detection Focused Solutions 1. CVE scanners 2. Redacting sensitive information
3. Bug Bounty 4. Alerting and monitoring
Security Principles 1. Don’t Trust the Client 2. Don’t Trust
Services 3rd Parties 3. Defense in Depth Secure by Default 4. Least Privilege 5. Fail Securely Explicitly
Learn More • Coinbase Security Blog: https://blog.coinbase.com/tagged/security • Cryptograve yard:
https://magoo.github.io/Blockchain-Graveyard/ • Adam Shostack, Learning to Threat Model for Security Professionals: https://www.linkedin.com/learning/learning-threat-modeling-for-security-professionals • OWASP: https://www.owasp.org/index.php/Security_by_Design_Principles • Brad Ediger, Advanced Rails: https://learning.oreilly.com/library/view/advanced-rails (security chapter) • Secure Headers Gem: https://github.com/twitter/secure_headers • Salus Gem: https://github.com/coinbase/salus • Adam Shostack, Threat Modeling: https://www.amazon.com/Threat-Modeling-Designing-Adam-Shostack/dp/1118809998 • Bundler Audit Gem: https://github.com/rubysec/bundler-audit • Brakeman Gem: https://github.com/presidentbeef/brakeman • Pundit Gem: https://github.com/varvet/pundit • Michal Zalewski, The Tangled Web: https://www.amazon.com/Tangled-Web-Securing-Modern-Applications/dp/1593273886
Resources • Cryptograve yard: https://magoo.github.io/Blockchain-Graveyard/ • Adam Shostack, Learning to
Threat Model for Security Professionals: https://www.linkedin.com/learning/learning-threat-modeling-for-security-professionals • OWASP: https://www.owasp.org/index.php/Security_by_Design_Principles • Brad Ediger, Advanced Rails: https://learning.oreilly.com/library/view/advanced-rails (security chapter) • Secure Headers Gem: https://github.com/twitter/secure_headers • Salus Gem: https://github.com/coinbase/salus • Adam Shostack, Threat Modeling: https://www.amazon.com/Threat-Modeling-Designing-Adam-Shostack/dp/1118809998 • Bundler Audit Gem: https://github.com/rubysec/bundler-audit • Brakeman Gem: https://github.com/presidentbeef/brakeman • Pundit Gem: https://github.com/varvet/pundit • Kirill Gorshkov: https://blog.smartdec.net/bug-vs-vulnerability-d6d4dc4068bd • Michal Zalewski, The Tangled Web: https://www.amazon.com/Tangled-Web-Securing-Modern-Applications/dp/1593273886
Image Resources • Dragon Glass Coin by Lisa Engler: https://dribbble.com/lisaengler
• Ruby on Rails logo: https://commons.wikimedia.org/wiki/File:Ruby_on_Rails_logo.svg • Game of Thrones Logo: https://commons.wikimedia.org/wiki/File:Game_of_Thrones_2011_logo.svg • Warning Sign: https://pixabay.com/vectors/warning-sign-30915/ • Daenerys’s image: https://3diphonewallpaper.com/daenerys-targaryen-game-of-thrones-iphone-wallpaper-9527/ • Cookie: http://www.publicdomainfiles.com/show_file.php?id=13968371414517 • Salus Logo: https://github.com/coinbase/salus • Brakeman Logo: https://github.com/presidentbeef/brakeman • Bundler Audit Logo: https://github.com/rubysec/bundler-audit • Jean Patch photo: https://www.flickr.com/photos/woolgenie/22805676928 • Duo logo and image: https://brandfolder.com/duo/public-brand-assets • Yubico logo and image: https://www.yubico.com/press/images/ • Google Authenticator Logo: https://en.wikipedia.org/wiki/Google_Authenticator • Jon Snow: https://images.app.goo.gl/prM2x1bFJiBdWWM27 • Bitmoji App
None