668 subscribers
Go offline with the Player FM app!
Podcasts Worth a Listen
SPONSORED


1 Ep. 42 - RevPar Problems, Real Talk: When Memes meet Metrics with Calvin Tilokee 47:59
141: Web Application Security, Part 2 with Scott Arciszewski
Manage episode 214305873 series 2410493
In this weeks episode we continue our discussion with Scott Arciszewski about all things Security and Cryptography. We start off the show by highlighting what a SQL injection attack is and the differences between (emulated) prepared statements. This leads us on to look into how to securely handle file uploads, what a reverse shell is and how to defend yourself against XSS/CSRF attacks. From here we touch upon the recent inclusion of libsodium into PHP, why mcrypt should be avoided, and the side-channel vulnerabilities that brought way to Meltdown and Spectre. Finally, we mention how computers generate seemingly random numbers, what a Web Application Firewall (WAF) is, and how WARD goes about protecting your systems.
Show Links
- Scott Arciszewski on Twitter
- Paragon Initiative Enterprises
- The 2018 Guide to Building Secure PHP Software
- Are PDO prepared statements sufficient to prevent SQL injection?
- Preventing SQL Injection in PHP Applications
- paragonie/easydb - Easy-to-use PDO wrapper for PHP projects.
- Security at the expense of usability comes at the expense of security.
- Security B-Sides Orlando 2017
- TimThumb WebShot Code Execution Exploit (Zeroday)
- Reverse shell !?!
- paragonie/anti-csrf - Full-Featured Anti-CSRF Library
- Using Libsodium in PHP Projects
- paragonie/sodium_compat - Pure PHP polyfill for ext/sodium
- libsodium
- It Turns Out, 2017 is the Year of Simply Secure PHP Cryptography
- The ECB Penguin
- Cache-timing attacks on AES
- Side-Channel Attacks on Everyday Applications
- Meltdown and Spectre
- PCID is now a critical performance/security feature on x86
- If You’re Typing the Word MCRYPT Into Your PHP Code, You’re Doing It Wrong
- Myths about /dev/urandom
- PHP - random_bytes
- PHP - random_int
- Ward - Web Application Realtime Defender
164 episodes
Manage episode 214305873 series 2410493
In this weeks episode we continue our discussion with Scott Arciszewski about all things Security and Cryptography. We start off the show by highlighting what a SQL injection attack is and the differences between (emulated) prepared statements. This leads us on to look into how to securely handle file uploads, what a reverse shell is and how to defend yourself against XSS/CSRF attacks. From here we touch upon the recent inclusion of libsodium into PHP, why mcrypt should be avoided, and the side-channel vulnerabilities that brought way to Meltdown and Spectre. Finally, we mention how computers generate seemingly random numbers, what a Web Application Firewall (WAF) is, and how WARD goes about protecting your systems.
Show Links
- Scott Arciszewski on Twitter
- Paragon Initiative Enterprises
- The 2018 Guide to Building Secure PHP Software
- Are PDO prepared statements sufficient to prevent SQL injection?
- Preventing SQL Injection in PHP Applications
- paragonie/easydb - Easy-to-use PDO wrapper for PHP projects.
- Security at the expense of usability comes at the expense of security.
- Security B-Sides Orlando 2017
- TimThumb WebShot Code Execution Exploit (Zeroday)
- Reverse shell !?!
- paragonie/anti-csrf - Full-Featured Anti-CSRF Library
- Using Libsodium in PHP Projects
- paragonie/sodium_compat - Pure PHP polyfill for ext/sodium
- libsodium
- It Turns Out, 2017 is the Year of Simply Secure PHP Cryptography
- The ECB Penguin
- Cache-timing attacks on AES
- Side-Channel Attacks on Everyday Applications
- Meltdown and Spectre
- PCID is now a critical performance/security feature on x86
- If You’re Typing the Word MCRYPT Into Your PHP Code, You’re Doing It Wrong
- Myths about /dev/urandom
- PHP - random_bytes
- PHP - random_int
- Ward - Web Application Realtime Defender
164 episodes
All episodes
×

1 164: Delving into Elixir with Keyvan Akbary 1:07:07


1 163: Building SaaS Products with Simon Bennett 48:10




1 161: Exploring Bitcoin with Mattias Geniar 1:14:26


1 160: Serverless PHP using Bref with Matthieu Napoli and Neal Brooks 51:21


1 159: PHP Test Tooling and RFC Roundup with Joe Watkins 56:37


1 158: Hexagonal Architecture (Ports and Adapters) with Matthias Noback 1:01:16


1 157: The Symfony Ecosystem with Nicolas Grekas 49:55


1 156: Running Symfony on AWS Lambda with Neal Brooks 57:42


1 155: Bridging the Security Gap with Scott Arciszewski 1:12:30


1 154: Why all the Curly Braces? with Scott Wlaschin 1:10:08






1 151: AWS, Golang and iOS Development with Alex Bilbie 1:00:22


1 150: PHP was not designed for that?! with Joe Watkins 44:38
Welcome to Player FM!
Player FM is scanning the web for high-quality podcasts for you to enjoy right now. It's the best podcast app and works on Android, iPhone, and the web. Signup to sync subscriptions across devices.