2020-014-Server Side Request Forgery defense, Tanya Janca, AppSec discussion
2020-014-Server Side Request Forgery defense, Tanya Janca, AppSec discussion

2020-014-Server Side Request Forgery defense, Tanya Janca, AppSec discussion

Mrs_Marong💞

48 min
News
Play

Description

<p>Tanya's AppSec Course</p> <p><a href= "https://www.shehackspurple.dev/server-side-request-forgery-ssrf-defenses"> <span style= "font-weight: 400;">https://www.shehackspurple.dev/server-side-request-forgery-ssrf-defenses</span></a></p> <p><a href="https://www.shehackspurple.dev"><span style= "font-weight: 400;">https://www.shehackspurple.dev</span></a></p> <p><span style="font-weight: 400;">Server-side request forgery -</span> <a href= "https://portswigger.net/web-security/ssrf"><span style= "font-weight: 400;">https://portswigger.net/web-security/ssrf</span></a></p> <p><span style="font-weight: 400;">What are differences between Stored XSS and SSRF? </span></p> <p><span style="font-weight: 400;">This requires a MITM type of issue?</span></p> <p><span style="font-weight: 400;">Doesn’t stored XSS get stored on the server?</span></p> <p><span style="font-weight: 400;">What conditions must exist for SSRF to be possible?</span></p> <p><span style="font-weight: 400;">What mitigations need to be in place for mitigation of SSRF? CORS? CSP?</span></p> <p><span style="font-weight: 400;">Would a WAF or mod_security be effective?</span></p> <p><span style="font-weight: 400;">Can it be completely mitigated or are there still ways around it?</span></p> <p><span style="font-weight: 400;">Part2 -next week</span></p> <p> </p> <p><span style="font-weight: 400;">Github actions -</span> <a href= "https://github.com/features/actions"><span style= "font-weight: 400;">https://github.com/features/actions</span></a></p> <p><span style="font-weight: 400;">How are these written? </span></p> <p><span style="font-weight: 400;">It looks like a marketplace format? How do they maintain code quality?</span></p> <p><span style="font-weight: 400;">What does it take setup the actions?</span></p> <p><span style="font-weight: 400;">It looks like IFTTT for DevOps?</span></p> <p><span style="font-weight: 400;">What kind of integrations does it allow for? Will it handle logins or API calls for you?</span></p> <p><span style="font-weight: 400;">Is it

Uploader

holly.cove

holly.cove

2020-014-Server Side Request Forgery defense, Tanya Janca, AppSec discussion - Listen Free | WowFM