A Logo

Feel free to include my content in your page via my
RSS feed

Help Irongeek.com pay for
bandwidth and research equipment:

Subscribestar or Patreon

Search Irongeek.com:

Affiliates:
Irongeek Button
Social-engineer-training Button

Help Irongeek.com pay for bandwidth and research equipment:

paypalpixle


Modern AppSec Gotchas - Fletcher Heisler (Circle City Con 2019 Videos) (Hacking Illustrated Series InfoSec Tutorial Videos)

Modern AppSec Gotchas
Fletcher Heisler

@fheisler
Circle City Con 2019

We keep building better web frameworks full of built-in security features, but we keep finding new ways to work around them! Modern web developers can typically afford to take a lot for granted when it comes to appsec, with languages and frameworks that by default enforce many decent security practices. Browsers are getting better at automatically protecting users and blocking unsafe content as well. However, that just makes it all the more important to know why these helpful features are in place and how best to leverage them, instead of ignoring, fighting against or disabling them. In this talk, we'll explore common patterns where developers most often choose to forego the built-in protection offered by their tools of choice. We'll cover where this happens, why it tends to happen, and how to catch these corner cases before they turn up in production. As a developer, it's easy to be lured into the trap that security is "already taken care of" by that shiny new {NodeJS package/Golang framework/JSX-on-the-blockchain}, but we'll also give some examples of insecure defaults in commonly relied on frameworks. Modern development comes with lots of helpful bells and whistles, but modern developers need to be more vigilant than ever when it comes to ensuring strong application security!

Fletcher is the founder and CEO of [Hunter2](https://hunter2.com), a company that provides engineering teams with modern appsec training that isn't lame; through an online platform of interactive labs, developers get hands-on practice exploiting and patching up real applications. Fletcher previously ran Real Python, an online community of hundreds of thousands learning modern web development and programming practices.

Back to Circle City Con 2019 Videos list

Printable version of this article

15 most recent posts on Irongeek.com:


If you would like to republish one of the articles from this site on your webpage or print journal please contact IronGeek.

Copyright 2020, IronGeek
Louisville / Kentuckiana Information Security Enthusiast