Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

XSS Mitigation - The State of the Art

Security BSides San Francisco via YouTube

Overview

Google, IBM & Meta Certificates – 40% Off
One Coursera Plus subscription covers most Professional Certificates on Coursera.
Unlock All Certificates
This talk explains how to defend web applications against cross-site scripting through browser protections, server-side mitigations, framework practices, threat modeling, and supply-chain security. It includes live demonstrations of XSS exploitation and defenses.

Syllabus

Intro
Main XSS variants
Web security model: Same Origin Policy, 1995
Juicy targets: Electron apps
Most common bypasses
Disable JavaScript
Trusted Types
Cookies security
The future of browser defenses
Server Side Rendering options
Auto Content Security Policy for Server Side Rendering
Templating engines-level mitigations
Static Application Security Testing (SAST)
Existing standards mitigations overview (aka security headers soupe)
The future of server side mitigations
Battlecards: XSS threat model
Frameworks and associated risks
Supply chain security: XSS specific risks Remote dependencies can be tampered with
XSS defense in depth

Taught by

Security BSides San Francisco

Reviews

Start your review of XSS Mitigation - The State of the Art

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.