Skip to content

Securing a web (site/app/api): hands on!

Photo of Don Bowman
Hosted By
Don B.
Securing a web (site/app/api): hands on!

Details

Didn't get a lot of comments on topics.
This is one i've been working on for a bit, covered in recent vid and blog https://www.agilicus.com/assess-web-security/

I will go through how one assess a web app/api/site for security. How to harden it, showing some of the tools.

I will then show some of the complex things you can do w/ a Web Application Firewall (WAF) using resty-lua-waf (https://github.com/p0pr0ck5/lua-resty-waf) as an examplke, if you are stuck with a weak app and no way to fix its code.

Topics:

  • Content-Security-Policy
  • XSS-*
  • Cross Origin Request Sharing
  • HTTP Strict Transport Security
  • TLS setup
  • DNS CAA

Feel free to open https://observatory.mozilla.org/analyze/www.rbcroyalbank.com and be amazed @ the score of 0/100 (F).

Photo of Waterloo Technology Chautauqua group
Waterloo Technology Chautauqua
See more events
Agilicus Incorporated
87 King St W #300 · Kitchener, ON