Mar 2023
6 Mon
7 Tue 04:00 PM – 05:00 PM IST
8 Wed
9 Thu
10 Fri
11 Sat
12 Sun
Mar 2023
6 Mon
7 Tue 04:00 PM – 05:00 PM IST
8 Wed
9 Thu
10 Fri
11 Sat
12 Sun
As the server-side of the web gets more secure due to secure coding and defensive technologies, attackers are shifting their focus to the low-hanging fruit. This is increasingly turning out to be the client-side. Injecting a few lines of JavaScript in to an application’s client-side can give an attacker access to all of the data and functionality from the backend. And the attack can also go undetected. Clear evidence of this is the theft of several hundreds of millions of credit card details, consistently over the last several years using this approach.
In this talk, the speaker will explain how such attacks work, and how you can detect them using a built-in feature of the browsers - Content Security Policy (CSP). CSP implementation often becomes a complex and effort intensive exercise. Using the lessons learned from implementing CSP for several organisations, Lavakumar Kuppan will share a simple approach to having an imperfect but practical and useful CSP in place.
Lavakumar Kuppan is founder at domdog.io
He has delivered talks on CSP at Rootconf and JSFoo
Purchase a subscription to access videos and to support Rootconf’s community activities.
Code of Conduct: Hasgeek’s Code of Conduct applies to all participants and speakers.
Contact information: For queries about Rootconf, contact Hasgeek at info@hasgeek.com or call (91)7676332020.