(In)secure Ajax-y Websites with PHP
Christian Wenz (16.Sep.2008 at 17:15)
Talk at Zend/PHP Conference & Expo 2008 (English - US)
A recent security audit of "Web 2.0" web sites showed that even though the code there is not plagued with legacy code from the last century (a common cause for security issues), the chance of exploiting insecure code is very high. There are several reasons for that: many APIs and lots of user generated content increase the attack surface, and the wide use of JavaScript gives more power to the application -- and to the attacker. Old attacks get more dangerous thanks to new twists, and new attacks prove that security is an on-going process. This session features many demos, war stories, and of course countermeasures. Better be paranoid than offline; in this session you will see how.
Quicklink: https://joind.in/386
By clicking this button you are declaring that you are the speaker responsible for it and a claim request will be sent to the administrator of the event.
If the claim is approved you will be able to edit the information for this talk.
Are you sure?



