According to a study, nine out of ten web applications have security vulnerabilities. Recent events proved that not only old legacy sites were successfully attacked, but also new and recent applications, built with the best intentions and also with security in mind. We will have a look at common attacks, new attacks, and new twists to old attacks that demonstrate why so many websites may be compromised. We will have a look at recent attacks that made mainstream media, analyze some aspects of them, and will provide guidelines and best practices to become website ten out of ten. This session, as usual, comes with code and demos.


Excellent over view of the state of things. I tend to get fairly far removed from where the security problems are, and talks like your's are a pretty good refresher. Very well organized and informative. Your examples were also quite helpful.

Very good session. Lots of exampled of the different vulnerabilities and how they can be exploited.