Security
Marius Grigaitis | NFQ
marius.grigaitis@nfq.lt
Let’s go by example
I think I saw this somewhere
And not only websites...
https://www.youtube.com/watch?v=00A36VABIA4
There must be a better way!
Protect yourself - 2FA
Protect yourself - default passwords
Duplicate passwords
Browse safer
Encrypt your disk
Social Engineering
Works in IT also
“Hey Daddy, I’m in a big problem. What’s your email password?”
Social Engineering
Lock your screen!
Lock your screen
Update your software
2. Protect your website
HTTPS
Misconfiguration
Misconfiguration
Misconfiguration
PHPInfo exposed
Misconfiguration
Directory listing
Misconfiguration
Misconfiguration
Misconfiguration
Not up to date
ImageMagick
ImageTragick
Insecure direct object access
Hard to enumerate ids?
Information disclosure?
Insecure direct object access
GET /events/1/delete
CSRF
Broken Auth
Broken Auth
Broken Auth
RFC 1149.5 specifies 4 as the standard IEEE-vetted random number.
Obligatory
Broken Auth
Password encoding - one way hash functions
Broken Auth
Is it?
MD5 is
broken!
Broken Auth
Broken Auth
Broken Auth
Broken Auth
XSS
XSS 101 - http://goo.gl/bgNVj2
XSS
XSS
Twig
SQL Injection
SQL Injection
Eval
No comments...
tl;dr
Users will send something nice
Anywhere
Secure by Default
Secure by Default
Contribute
Follow the news!
Question?