YoVDO

Practical AppSec - Quick Wins for More Secure Software

Offered By: LASCON via YouTube

Tags

LASCON Courses SQL Injection Courses Application Security (AppSec) Courses Application Development Courses Software Security Courses Threat Modeling Courses

Course Description

Overview

Discover practical strategies for enhancing application security in this 37-minute conference talk from LASCON 2014. Learn how to prioritize and implement quick wins to improve your software's security posture with limited resources. Explore various approaches including manual penetration testing, source code review, automated scanning, web application firewalls, threat modeling, and developer training. Gain insights on working effectively with development teams for remediation efforts. Understand how to measure progress and demonstrate improvement using a popular software security maturity model. Walk away with specific, actionable steps to strengthen your applications' security and raise the bar for potential attackers.

Syllabus

Intro
Sabre
About Dave
AppSec Mission
Complications
General Thoughts
Burp
Quick Wins
Finding Attack Surfaces
SSL Configuration
Sequel Injection
Crosssite Scripting
HTTP Response Headers
Engage Developers
AppSec maturity model
Alternatives


Taught by

LASCON

Related Courses

Software Engineering for SaaS
University of California, Berkeley via Coursera
MongoDB for Developers
MongoDB University
Android: introducción a la programación
Universitat Politècnica de València via UPV [X]
Extending SAP Products with SAP HANA Cloud Platform
SAP Learning
Two Speed IT: How Companies Can Surf the Digital Wave, a BCG Perspective
École Centrale Paris via Coursera