Talk in English - UK at ConFoo 2012
View Slides: http://talks.bluesmoon.info/iwygwyetg/input-sanitization.pdf
Short URL: https://joind.in/talk/c4020
Code injection into web apps is not a new phenomenon. It's been a constant on the web even longer than IE6. It's been around since the very first .cgi scripts were chmod +x'ed, resulting in a chroot 0wn3d.
Code injection is mainly brought about by web programmers not making sure that the input received from users is what was expected.
This talk, will concentrate mainly on XSS injection, but will also talk a little about SQLi and CSRF. We'll go over the kinds of programming mistakes that result in code injection, and how to change your mindset to prevent these issues.