Showing posts with label OWASP. Show all posts
Showing posts with label OWASP. Show all posts

Friday, February 27, 2015

OWASP NZ Day 2015 - OWASP Top 10 and ASP.NET MVC

In the opening talk for the OWASP NZ Day, Kirk introduced the OWASP Top 10 by zipping through each of the 10 issues and briefly explained them.

We also covered some of the protections that are either built in to ASP.NET MVC or available as options that help to combat these common attacks.

Download slides: 2015-02-27-OWASPMVC-print.pdf (PDF, 6mb)

Friday, August 31, 2012

OWASP NZ - Down to the Wire

Presented by Mark Haworth and Kirk Jackson at the OWASP NZ Day 2012, on 31 August 2012.
You've built the flashiest web app your cow-orkers have ever seen. Your boss loves you, and nominates you for a promotion next financial year. You've leveraged the latest hip web framework, and have jaxed your ajax to the max. But have you done everything you can to make your application secure? Are you perhaps, in fact, doing a little _too much_? A common issue we've come across in the past few years is applications that share too much information over the wire, or trust too much of what they receive. In this talk we'll look at some common pitfalls and techniques to counter them in modern web applications. Let's go down to the wire.
PDF (5.2mb)

Thursday, July 7, 2011

OWASP NZ - File Uploads

Kirk Jackson presented at the 2011 OWASP NZ Day. The talk was titled "File Uploads are EVIL!".

Allowing users to upload files to your website and later download them is complicated to get right. In this talk, Kirk tried to distill some of the knowledge and experience collected during penetration testing client applications and give advice on how to safely receive, store and return user-generated files.

Download the whitepaper: OWASP_NZDay_2011_KirkJackson_FileUploadConsiderations.pdf