Media Summary: Cross-Site Request Forgery (CSRF) attacks are one of the critical threats for web applications. In this presentation, we focus on ... Increasingly, compiler writers are taking advantage of undefined behaviors in the C and C++ programming languages to improve ... Cross-Origin Resource Sharing (CORS) is a mechanism for relaxing the Same Origin Policy to enable communication between ...

Appsec Eu 2017 Analysis And - Detailed Analysis & Overview

Cross-Site Request Forgery (CSRF) attacks are one of the critical threats for web applications. In this presentation, we focus on ... Increasingly, compiler writers are taking advantage of undefined behaviors in the C and C++ programming languages to improve ... Cross-Origin Resource Sharing (CORS) is a mechanism for relaxing the Same Origin Policy to enable communication between ... Full title: Don't Learn, Don't See, Don't Run: Recently, an anonymous open source developer decides to remove his code (left-pad) from a public repository. Shortly thereafter ... Managed by the official OWASP Media Project

Ransomware is center stage, as campaigns are practically guaranteed financial gain. Cyber-criminals profit hundreds of millions ... Configuration management tools such as Puppet or Chef have become increasingly popular as many organizations shifted ... Developers needs prescriptive guidance on preemptive design and coding techniques. This can be done blindly or in alignment ... Containers, microservices, the 12 factor app methodology, unikernels; all of these are examples of a theme in modern ... Last year we proved that the whitelist-based approach of Content Security Policy (CSP) is flawed and proposed an alternative ...

Photo Gallery

AppSec EU 2017 Analysis And Detection Of Authentication Cross Site Request Forgery by Luca Compagna
AppSec EU 2017 Dangerous Optimizations And The Loss Of Causality by Robert C  Seacord
AppSec EU 2017 Exploiting CORS Misconfigurations For Bitcoins And Bounties by James Kettle
AppSec EU 2017 Application Security For DevSecOps by Joseph Feiman
AppSec EU 2017 An SDLC For The DevSecOps Era by Zane Lackey
AppSec EU 2017 Could A Few Lines Of Code F!#ck It All Up! by Erez Yalon
AppSec EU 2017 LT Is Software Eating Security? by Dave Anderson
AppSec EU 2017 What The Kidnapping And Ransom Economy Teaches Us About Ransomware by J Grossman
AppSec EU 2017 Creating An AppSec Pipeline With Containers In A Week by Jeroen Willemsen
AppSec EU 2017 Improving The Security Of Software Defined Infrastructures by Theodoor Scholte
AppSec EU 2017 Threat Modeling with PASTA by Tony UcedaVelez
AppSec EU 2017 Security And The Self Contained Unit Of Software by Gareth Rushgrove
View Detailed Profile
AppSec EU 2017 Analysis And Detection Of Authentication Cross Site Request Forgery by Luca Compagna

AppSec EU 2017 Analysis And Detection Of Authentication Cross Site Request Forgery by Luca Compagna

Cross-Site Request Forgery (CSRF) attacks are one of the critical threats for web applications. In this presentation, we focus on ...

AppSec EU 2017 Dangerous Optimizations And The Loss Of Causality by Robert C  Seacord

AppSec EU 2017 Dangerous Optimizations And The Loss Of Causality by Robert C Seacord

Increasingly, compiler writers are taking advantage of undefined behaviors in the C and C++ programming languages to improve ...

AppSec EU 2017 Exploiting CORS Misconfigurations For Bitcoins And Bounties by James Kettle

AppSec EU 2017 Exploiting CORS Misconfigurations For Bitcoins And Bounties by James Kettle

Cross-Origin Resource Sharing (CORS) is a mechanism for relaxing the Same Origin Policy to enable communication between ...

AppSec EU 2017 Application Security For DevSecOps by Joseph Feiman

AppSec EU 2017 Application Security For DevSecOps by Joseph Feiman

Full title: Don't Learn, Don't See, Don't Run:

AppSec EU 2017 An SDLC For The DevSecOps Era by Zane Lackey

AppSec EU 2017 An SDLC For The DevSecOps Era by Zane Lackey

The standard approaches for web

AppSec EU 2017 Could A Few Lines Of Code F!#ck It All Up! by Erez Yalon

AppSec EU 2017 Could A Few Lines Of Code F!#ck It All Up! by Erez Yalon

Recently, an anonymous open source developer decides to remove his code (left-pad) from a public repository. Shortly thereafter ...

AppSec EU 2017 LT Is Software Eating Security? by Dave Anderson

AppSec EU 2017 LT Is Software Eating Security? by Dave Anderson

Managed by the official OWASP Media Project https://www.owasp.org/index.php/OWASP_Media_Project.

AppSec EU 2017 What The Kidnapping And Ransom Economy Teaches Us About Ransomware by J Grossman

AppSec EU 2017 What The Kidnapping And Ransom Economy Teaches Us About Ransomware by J Grossman

Ransomware is center stage, as campaigns are practically guaranteed financial gain. Cyber-criminals profit hundreds of millions ...

AppSec EU 2017 Creating An AppSec Pipeline With Containers In A Week by Jeroen Willemsen

AppSec EU 2017 Creating An AppSec Pipeline With Containers In A Week by Jeroen Willemsen

Full title: Creating An

AppSec EU 2017 Improving The Security Of Software Defined Infrastructures by Theodoor Scholte

AppSec EU 2017 Improving The Security Of Software Defined Infrastructures by Theodoor Scholte

Configuration management tools such as Puppet or Chef have become increasingly popular as many organizations shifted ...

AppSec EU 2017 Threat Modeling with PASTA by Tony UcedaVelez

AppSec EU 2017 Threat Modeling with PASTA by Tony UcedaVelez

Developers needs prescriptive guidance on preemptive design and coding techniques. This can be done blindly or in alignment ...

AppSec EU 2017 Security And The Self Contained Unit Of Software by Gareth Rushgrove

AppSec EU 2017 Security And The Self Contained Unit Of Software by Gareth Rushgrove

Containers, microservices, the 12 factor app methodology, unikernels; all of these are examples of a theme in modern ...

AppSec EU 2017 So We Broke All CSPs    You Won't Guess What Happened Next by Michele Spagnuolo

AppSec EU 2017 So We Broke All CSPs You Won't Guess What Happened Next by Michele Spagnuolo

Last year we proved that the whitelist-based approach of Content Security Policy (CSP) is flawed and proposed an alternative ...