You've built the flashiest web app your cow-orkers have ever seen. Your boss loves you, and nominates you for a promotion next financial year. You've leveraged the latest hip web framework, and have jaxed your ajax to the max. But have you done everything you can to make your application secure? Are you perhaps, in fact, doing a little _too much_? A common issue we've come across in the past few years is applications that share too much information over the wire, or trust too much of what they receive. In this talk we'll look at some common pitfalls and techniques to counter them in modern web applications. Let's go down to the wire.PDF (5.2mb)
Get the latest web and dev security information from the Hack-Ed team.
Friday, August 31, 2012
OWASP NZ - Down to the Wire
Presented by Mark Haworth and Kirk Jackson at the OWASP NZ Day 2012, on 31 August 2012.
Sunday, November 6, 2011
Kiwicon 5 - X-Excess
Mike Haworth and Kirk Jackson presented a talk at Kiwicon 5 titled "X-Excess":
Mobile applications are the new hotness and it seems everyone wants to build one. Unfortunately you have to build new app for each platform, so frameworks are popping up to bridge that gap. We look at some abuses of one framework and the implication for your shiny new gadget. Surely we can't bug a phone using XSS? Seems also there is a little known crowd out of Washington that have been swept up in the enthusiasm of exposing JavaScript APIs so now the same issues apply to your desktop too.Download the presentation here: x-excess_v1.1.pdf (1mb)
Sunday, August 28, 2011
Code Camp Auckland 2011 - Web Security: The latest 'n' greatest
In this talk at Code Camp Auckland, Kirk discussed the latest protections that have been added to web browsers to combat the common threats to your web applications.
He covered Content Security Policy (CSP), HTTP Strict Transport Security (HSTS) and the X-Frame-Options headers, as well as discussing how to safely host user-generated files for download.
View the slides here: CC2011-KirkJackson.pdf (6mb)
He covered Content Security Policy (CSP), HTTP Strict Transport Security (HSTS) and the X-Frame-Options headers, as well as discussing how to safely host user-generated files for download.
View the slides here: CC2011-KirkJackson.pdf (6mb)
Thursday, August 25, 2011
TechEd 2011 - Hack-Ed: Boost your Defences!
Andy Prow and Kirk Jackson presented two talks at TechEd NZ 2011. The second talk was titled "Boost your Defences!":
Running a website is a risky business. Applications within organisations and on the internet are under attack all the time, by all kinds of people. How do you make your ASP.NET WebForms, MVC or SharePoint application as secure as possible? Which protection mechanisms are built in to the platform, and what are the recommended techniques for those that aren't? Come along to this talk where we will cover techniques for protecting your application from all of the common web attacks.
Further resources:
Wednesday, August 24, 2011
TechEd 2011 - Hack-Ed: The Attackers are Coming!
Andy Prow and Kirk Jackson presented two talks at TechEd NZ 2011. The first talk was titled "The Attackers are Coming!":
The internet is a fast moving business, web applications in 2011 are being attacked in new ways, using new tools and techniques.
This talk will cover the state of the art in web security, and have some fun sharing stories of sites that have been attacked and how well they survived.
Further resources:
Tuesday, July 26, 2011
Summer of Tech - Web Security (Gum) Bootcamp
Kirk and Andy presented a Web Security (Gum) Bootcamp session at the Wellington Summer of Tech:
Get ya boots on for a true down-and-dirty hands-on web-security session with Kirk and Andy from Aura InfoSec.
This session will cover what's out there in the wild attacking your websites, why you should care and YES there are things you can do about it.
For starters, if you plan to ever own, develop, design, maintain, host, work-on-in-any-way or in fact even browse-to a website at some point in your life, the you must attend this web-sec bootcamp!Download the slides: 2011-07-26-SummerOfTech.pdf (4mb)
Thursday, July 14, 2011
WDCNZ - Web Security: Get Ahead(er)
Kirk Jackson presented at the inaugural WDCNZ conference in Wellington.
This talk covered new browser support for Content Security Policy and HTTP Strict Transport Security headers, as well as miscellaneous other web security techniques to protect your applications from XSS, man-in-the-middle and other attacks.
Download the slides: KirkJackson-WDCNZ-GetAHeader-online.pdf (1.3mb)
This talk covered new browser support for Content Security Policy and HTTP Strict Transport Security headers, as well as miscellaneous other web security techniques to protect your applications from XSS, man-in-the-middle and other attacks.
Download the slides: KirkJackson-WDCNZ-GetAHeader-online.pdf (1.3mb)
Thursday, July 7, 2011
OWASP NZ - File Uploads
Kirk Jackson presented at the 2011 OWASP NZ Day. The talk was titled "File Uploads are EVIL!".
Allowing users to upload files to your website and later download them is complicated to get right. In this talk, Kirk tried to distill some of the knowledge and experience collected during penetration testing client applications and give advice on how to safely receive, store and return user-generated files.
Download the whitepaper: OWASP_NZDay_2011_KirkJackson_FileUploadConsiderations.pdf
Allowing users to upload files to your website and later download them is complicated to get right. In this talk, Kirk tried to distill some of the knowledge and experience collected during penetration testing client applications and give advice on how to safely receive, store and return user-generated files.
Download the whitepaper: OWASP_NZDay_2011_KirkJackson_FileUploadConsiderations.pdf
Wednesday, September 1, 2010
TechEd 2010: Hack-Ed II: Stop the hacking
At Microsoft TechEd NZ 2010, Kirk and Andy presented a talk titled "Hack-Ed II: Stop the hacking".
How do you defend your website against the attacks the bad guys will throw at it? This code-focussed talk will cover some tips and tricks, out of the box features and extensions to make your web applications as strong as possible.https://channel9.msdn.com/Events/TechEd/NewZealand/2010/SEC302
TechEd 2010: Hack-Ed: The hacking never stops
At Microsoft TechEd NZ 2010, Kirk and Andy presented a talk titled "Hack-Ed: The hacking never stops".
A video of the talk is available on Channel9:
https://channel9.msdn.com/Events/TechEd/NewZealand/2010/SEC301
Don't let down your defenses - the bad guys won't! This session focuses on the cool tricks that the bad guys use to attack your website, and will help you become a better developer.
A video of the talk is available on Channel9:
https://channel9.msdn.com/Events/TechEd/NewZealand/2010/SEC301
Wednesday, September 16, 2009
TechEd 2009: Hack-Ed: Teaching the Good Guys Bad Tricks
At Microsoft TechEd NZ 2009, Kirk and Andy presented their first Hack-Ed themed talk titled "Teaching the Good Guys Bad Tricks".
A video recording of the talk is available on Channel9:
https://channel9.msdn.com/Events/TechEd/NewZealand/2009/SEC313
A video recording of the talk is available on Channel9:
https://channel9.msdn.com/Events/TechEd/NewZealand/2009/SEC313
Subscribe to:
Posts (Atom)