Feeling secure? - notes from the field

Paul Lemon (09.Oct.2011 at 10:00)
Talk at PHP North West 2011 (English - UK)

Rating: 5 of 5

I'll be sharing our agency experience of developing secure web applications for some of the UK's leading high street banks and brands with a focus on the pitfalls you face when developing code in PHP. The talk will contain specific details on the many attack vectors that hackers will use to attempt to access and exploit your site and how you can improve your development process to avoid them.
Topics covered will include some old chestnuts like XSS (Cross Site Scripting) and SQL injection through to issues like XSRF (Cross Site Request Forgery) and Session Hijacking.
The talk is aimed at developers who have perhaps not truly considered security of their applications before to developers who would like to extend their knowledge. The talk is aimed at software developers and will contain practical code-based examples and solutions.

Who are you?

Claim talk

By clicking this button you are declaring that you are the speaker responsible for it and a claim request will be sent to the administrator of the event.

If the claim is approved you will be able to edit the information for this talk.

Are you sure?

 
Comments closed.

Comments

Rating: 5 of 5

09.Oct.2011 at 10:39 by Ben Nuttall via api

Fantastic talk, brilliant speaker, really useful points and well researched security issues discussed.

Rating: 5 of 5

09.Oct.2011 at 11:19 by Anthony Doherty

Great talk, Paul covered those things we already know in order to reinforce their importance and to make sure that every aspect of those vulnerabilities was understood - necessary to avoid complacency.

Comprehensive coverage of different flavours of common vulnerabilities with deliberately short code examples.

One of those talks where you walk away with new things to try, but also a few jobs to do. Would like to see the extended version of this covering XSRF and more.

Rating: 4 of 5

09.Oct.2011 at 12:10 by Luke Richards

I liked the talk although I was a little disappointed that it was the usual suspects that were covered. Having said that I understand why they were. The topics were well covered and it's good to be reminded of the security aspects. Thanks.

Rating: 4 of 5

09.Oct.2011 at 17:24 by Elliot Ward

Good talk and well delivered, though frustrating that there wasn't nearly enough time to give the topics enough depth; this was no fault of Paul's and I'd like to see him talk again on this topic in a longer time slot.

Rating: 4 of 5

09.Oct.2011 at 19:08 by Mike Holloway

Covered topics that I was familiar with but was well delivered and did pick up a couple of useful nuggets (such as the php.ini stuff)

Rating: 5 of 5

09.Oct.2011 at 20:05 by Jake Worrell

I found this to be a particularly good talk, and a good speaker. would have been great to have had more time to cover some of the other topics.

Rating: 4 of 5

09.Oct.2011 at 20:21 by Dan Rooke

Good talk and intro to some of the most common issues. Would be good to see same level of coverage for other issues in future.

Rating: 4 of 5

09.Oct.2011 at 20:50 by Petr Rybak

Well delivered recapitulation of the most important security rules. Again, the whole day could be easily spent on going into more details but I liked that Paul just picked the ones he believed were the most important and only focused on them which prevented turning the talk into a fast forward slideshow.

Rating: 5 of 5

09.Oct.2011 at 22:08 by Remon van de Kamp

Even though I knew most of the stuff it's good to get them hammered in every once in a while because it's just so important, and as Paul correctly said we tend to get a bit complacent over time when it comes to security.
Paul is a very good speaker; very confident, relaxed and really knows his stuff. I liked this presentation a lot!

Rating: 4 of 5

10.Oct.2011 at 08:32 by Volker Dusch

A nice short introduction into php/web security with a lot of good and valid points getting in some of the promised 'from the field' experience but not as much as I had hoped to.

It was a very nice unconf talk and I'd like to the 45/60 minute version at unconf EU or some other conference!

Rating: 5 of 5

10.Oct.2011 at 09:04 by Tim Curzon

One of the best talks of the conference - I wish Paul had had a full hour, no, 2 hours to go through his material. Really fascinating subject, excellently presented and with clear code examples to boot.

A note to the conference organisers - this really should have been moved to the Saturday - people need to know this stuff.

Rating: 5 of 5

10.Oct.2011 at 09:53 by Robert Goldsmith

A very good talk from a quality speaker. This talk really should have been given more time but credit to Paul for managing to squeeze so much into the short timeslot :) I thought the examples he gave were some of the clearest I've seen on a number of well-known but often less-well understood attack vectors and he had some interesting points (such as [removed] protocol urls) that are often forgotten about.

Rating: 5 of 5

10.Oct.2011 at 11:05 by M1ke

A subject more deserving of a week's training than a half hour talk, but Paul presented the main topics clearly, discussed them well and kept things focussed and to the point throughout. I even learnt something new in respect of the injection attacks into the href attribute, and the only negative point to make is that I now have to start combing my code base to see if there are any vectors for that particular issue!

Rating: 5 of 5

10.Oct.2011 at 13:09 by Jo B

Very interesting talk and good for a reference point, just a shame it wasn't longer!

Rating: 5 of 5

10.Oct.2011 at 14:12 by Stephen Melrose

Great talk. Engaging and didn't slow in pace.

It did cover the basics instead of more complex security problems, but then with those being the top reported security holes it made sense (this was explained in the talk).

I think this talk would be much better suited for an hour slot instead of 30 mins. That way the basics can be covered in the first half, with the remaining spent on more complex security holes like CSRF.

Rating: 5 of 5

10.Oct.2011 at 16:29 by Alex Butter

Excellent presentation. As others have said, there's nothing really new in the talk, but it's great to be reminded of what we should look out for.

Session could easily have been twice as long and just as entertaining and interesting.

Cloud server hosting by Combell Combell      © Joind.in 2012