Loading…
SecAppDev 2017 has ended
Tuesday, February 28 • 15:40 - 17:10
Modern Web Application Defenses against Dangerous Network Attacks (Part 2)

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Do you have any idea how many files you send to the user are modified in transit? How much sensitive information is up for grabs to an eavesdropper? Or whether there is an attacker sitting in the middle, with the ability to carry out a dangerous SSL Stripping attack?

In the past few years, a secure communication channel has become more important than ever, and browsers are actively pushing developers towards using HTTPS. Therefore, simply deploying sensitive parts of your application over HTTPS is no longer sufficient. You need to move all of your content to HTTPS, and deploy additional security policies to establish a secure end-to-end communication channel.

In this session, participants will learn through hands-on experience why a partial HTTPS deployment can easily be undermined by easy-to-execute network attacks. We will cover common (non-cryptographic) attacks on HTTPS applications, and how they are countered by the newest HTTPS security policies, such as HTTP Strict Transport Security (HSTS) and HTTP Public Key Pinning (HPKP). You will walk away with an up-to-date list of best practices for deploying your applications over HTTPS.

Attendees are required to bring a laptop with VirtualBox installed. If you have restricted access to the BIOS settings, please make sure Virtualization is enabled up front.

The training image is available for download at the following URL: https://people.cs.kuleuven.be/philippe.deryck/training/secappdev2017.ova  

Speakers
avatar for Philippe De Ryck

Philippe De Ryck

Founder, Pragmatic Web Security
Philippe De Ryck helps developers protect companies through better web security. As the founder of Pragmatic Web Security, he travels the world to train developers on web security and security engineering. His Ph.D. in web security from KU Leuven lies at the basis of his exceptional... Read More →



Tuesday February 28, 2017 15:40 - 17:10 CET
Room: Van Hamaele

Attendees (5)