YoVDO

Cross-Tenant Request Forgery Attack in Multi-Tenancy Environments

Offered By: OWASP Foundation via YouTube

Tags

Web Application Security Courses OAuth Courses Cloud Security Courses API Security Courses Data Privacy Courses Multi-Tenancy Courses

Course Description

Overview

Save Big on Coursera Plus. 7,000+ courses at $160 off. Limited Time Only!
Explore the critical security vulnerability of Cross-Tenant Request Forgery Attacks in multi-tenancy environments through this informative conference talk. Delve into the complexities of implementing OAuth in SaaS platforms, particularly when supporting multiple customers. Understand the challenges and potential risks associated with 2LO (Client Credential or JWT bearer) implementations in multi-tenant settings. Learn how attackers can exploit these vulnerabilities to compromise co-existing tenants and access their data undetected. Discover the concept of "Cross-Tenant Request Forgery" and gain insights into proper implementation techniques, vendor-specific remediations, and best practices for securing multi-tenant environments. Benefit from the expertise of Albert Yu, co-founder and CTO of Anzenna Inc., and Alan Bishop, lead software developer at Anzenna, as they share their extensive experience in building secure infrastructures and identifying web application security issues.

Syllabus

Cross-Tenant Request Forgery Attack in Multi-Tenancy Environments - Albert Yu & Alan Bishop


Taught by

OWASP Foundation

Related Courses

Designing RESTful APIs
Udacity
API Design and Fundamentals of Google Cloud's Apigee API Platform
Google Cloud via Coursera
API Development on Google Cloud's Apigee API Platform
Google Cloud via Coursera
API Security on Google Cloud's Apigee API Platform
Google Cloud via Coursera
Developing APIs with Google Cloud's Apigee API Platform
Google Cloud via Coursera