About JSFoo Coimbatore
JSFoo Coimbatore is a single-day conference with talks, Birds of Feather (BOF) sessions and speaker connect sessions. The conference will be held on Friday, 5 July, at Dr.G.R.Damodaran College of Science, Coimbatore.
JSFoo Coimbatore features talks on:
- How to secure your web applications by identifying vulnerabilities.
- Leveraging Web Application Vulnerabilities for Resourceful Intelligence Gathering.
- Case studies of performance improvements and using the modular approach to building front-ends.
- Node.js and good engineering practices such as logging, debugging and integrating security into your applications.
- WebSDK: switching between service providers on the fly.
JSFoo Coimbatore 2019 sponsors:
For inquiries on tickets and sponsorships, call the JSFoo Coimbatore team on 7676332020 or write to us on email@example.com
Secure web application - Hands on workshop
In this workshop we will be using the Damn Vulnerable NodeJS Application(DVNA) to demonstrate the OWASP top ten vulnerabilities. Initially participants will try to exploit, then understand and fix the vulnerability. We will use Kali linux to demostrate how to scan and find some of the vulnerabilities. If time permits we will try to explain, how to build secure containerized application and setting up CI/CD scanner.
Steps for every vulnerability:
Below vulnerabilities will be covered
1. SQL and command Injection
2. Broken Authentication
3. Sensitive Data Exposure
4. XML External Entities
5. Broken Access Control
6. Security Misconfiguration
7. Cross-Site Scripting (XSS)
8. Insecure Deserialization
9. Using Components with Known Vulnerabilities
10. Cross Site Request Forgery
11. Unvaidated Redirects and Forwards
If Kali linux installed - participants will get to know how to scan the possible vulnerability.
If time permits - hands on or else just demonstration for the below:
1. Securing Containerized application
2. Setting up security scanner pipeline in CI/CD
Laptops - Installed docker
Nice to have(not mandatory):
We are group of Thoughtworks, extensively using Nodejs application. Below are the links to speakers profile in LinkedIn