- Technology
- Cybersecurity
- Offensive Security
- Penetration Testing
- Web Application Penetration Testing
- Cross-Site Scripting (XSS)
- Technology
- Cybersecurity
- Offensive Security
- Penetration Testing
- Web Application Penetration Testing
- SQL Injection
- Technology
- Programming
- Software Engineering
- Software Development Methodologies
- Software Development Life Cycle
The Path of Secure Software Development - AppSec EU 2017
Learn the Skills Netflix, Meta, and Capital One Actually Hire For
Learn AI, Data Science & Business — Earn Certificates That Get You Hired
Overview
Syllabus
Intro
OWASP Top 10 Risks - 2013
Cyber attacks
OWASP Application Security Verification Standard (ASVS)
OWASP ASVS
Verify for Security Early and Often
SOL injection example
Parameterize Queries
XSS Example
Contextual Encoding Libraries
Example of Validations
2nd Order SQL Injection Example
CS. Implement Identity and Authentication Controls
Strong cryptographic algorithms
Secure Password Storage
C5. Password Storage - How Not To Do It!
C5. Error Messages - How Not To Do It!
C5. Risks Addressed
Implement Appropriate Access Controls
Implement Logging and Intrusion Detection
Risks Addressed - All Top Ten!
Current state of software
Unmanaged 3 Party Components
Don't leak information
@OWASP Controls
Taught by
OWASP Foundation