YoVDO

Railsgoat - Rails Attack and Defense

Offered By: LASCON via YouTube

Tags

LASCON Courses Agile Development Courses OWASP Top 10 Courses

Course Description

Overview

Explore a 32-minute conference talk from LASCON's Developer Track that delves into RailsGoat, an OWASP project designed to address security vulnerabilities in Rails applications. Learn about common security issues aligned with the OWASP Top 10, discover solutions for remediation, and understand attack scenarios specific to Rails. Gain insights into the motivation behind creating this free and open training tool for the Rails and Ruby ecosystem. Follow along as the speakers discuss mass assignment vulnerabilities, provide a tutorial on getting started with RailsGoat, and outline the project's roadmap. Understand the importance of security in Agile development environments and how RailsGoat can benefit Rails-based development teams. Get information on supported Rails versions, early adopter models, and future plans for the project, including potential expansion to Sinatra.

Syllabus

Intro
Companies using Rails
Demographics
Tutorial credentials
Teaser video
Mass Assignment
Railsgoat
Getting started
Roadmap
Rails versions
Questions
Future plans
Early adopter model
Sinatra


Taught by

LASCON

Related Courses

Comparing WAF and RASP - Why?
LASCON via YouTube
API Security - Is it the New Application Attack Surface and How to Secure at Enterprise Scale
LASCON via YouTube
Privacy Impact Assessments - How Much Privacy Is Enough?
LASCON via YouTube
Your Frontier Defense - Understanding Web Application Firewalls
LASCON via YouTube
Doing This One Crazy Thing Will Change Your AppSec Program Forever
LASCON via YouTube