GitHub
a p p s e c
GitHub a p p s e c Ben Toews XSS, CSRF, RCE, oh my! 0b 95 ce 8e - - PowerPoint PPT Presentation
GitHub a p p s e c Ben Toews XSS, CSRF, RCE, oh my! 0b 95 ce 8e d9 5a f4 08 55 6d 75 d9 8d cd 29 45 cd 26 6d 37 b9 fb 3b 5c 77 9d cd 9a 73 9b 5c 48 19 25 3e 60 d3 96 6c ee a3 26 e5 9b 34 4c 9d 6d c3 3a 99 86 97 8b 1e 3b 3a 3e ea 57 9d ed 37 15
a p p s e c
Ben Toews
$50,100 1920 submissions 57 paid 12 months
they’re coming…
demo
A2: Cross-Site Scripting
A3: Weak authentication and sessions
A5: Cross-Site Request Forgery
<img src=“https://github.com/user/destroy”>
A9: Insufficient Transport Layer Protection
A9: Insufficient Transport Layer Protection
HTTPS
A9: Insufficient Transport Layer Protection
HTTPS HSTS
A9: Insufficient Transport Layer Protection
HTTPS HSTS HSTS Preload
A9: Insufficient Transport Layer Protection
A9: Insufficient Transport Layer Protection
HTTPS HSTS HSTS Preload Public Key Pinning
boringSecurity
security is hard
@mastahyeti