International PHP Conference |
October 21 - 25, 2019 in Munich

Practical Security in Web Applications

Session
This talk originates from the archive. To the CURRENT program
Until conference starts: ✓ PS Classic Mini or Arduino Starter Kit for free ✓ Group discount ✓ 2 in 1 conference package Register now
Infos
Tuesday, June 4 2019
10:30 - 11:15

Explore effective methods to identify & avoid the most common and devastating security pitfalls in Web Applications.

When it comes to an enterprise’s exposure to security vulnerabilities, one could easily argue that its web presence is by far its greatest threat. There are many ways to build vulnerable applications and a few effective ways to "build them right". We’ll instrument you to stay on right side of this equation.

Agenda:

Basic Resources and Tooling

  • We’ll look at the OWASP Top 10
  • Open-Source Code Analysis for your CI/CD
  • Open-Source Security Scanning

Low-level Threat Avoidance

  • Avoiding SQL Injections — Dangers of not properly-using an ORM
  • Avoiding CSRF
  • Avoiding XSS
    • Data Scrubbing
    • Data Rendering

Application Threat Avoidance

  • User Authentication / Password Hashing
  • OAuth Security
  • Resource Access
    • Multi Tenancy: Users & Companies

Architectural Considerations

  • Systems Architecture
  • Credentials Handling

Stay tuned!

Behind the Tracks of IPC

PHP Development
Best Practices & Application

Web Development
Web Development & more

JavaScript Development
All about JavaScript

Agile & Culture
Agility has become mainstream

Architecture
Concepts & Environments

Web Security
All about Web Security

Testing & Quality
An overview of the most important topics

DevOps
DevOps is a philosophy