Intro to Application Security in ColdFusion

Comments

Hi, I'm so excited that I have found this your post because I have been searching for some information about it almost three hours.

Posted By: christian louboutin shoes On: 08/03/11 1:32 AM

You miss 100 percent of the shots you never take.

Posted By: Louis Vuitton On: 08/03/11 1:38 AM

Interesting read!!! Your website is fantastic with informative content which i like to add to my favourites.

Posted By: Louboutin Shoes Outlet On: 08/30/11 1:42 AM

Interesting read!!! Your website is fantastic with informative content which i like to add to my favourites.

Posted By: Louboutin Shoes Outlet On: 08/30/11 1:42 AM

good

Posted By: seo On: 09/10/11 4:50 PM

Dissertation research methodology chapter writing is of immense significance for the reason that it reveals how profoundly you have made the research for your papers. Find out the tips to write a dissertation methodology chapter.

Posted By: Dissertation methodology On: 09/15/11 7:48 AM

Dissertation research methodology chapter writing is of immense significance for the reason that it reveals how profoundly you have made the research for your papers. Find out the tips to write a dissertation methodology chapter.

Posted By: Dissertation methodology On: 09/15/11 7:48 AM

Hot damn, looking pretty ufseul buddy.

Posted By: Cady On: 11/24/11 9:42 AM

XwvGmp , [url=http://zowchifomjau.com/]zowchifomjau[/url], [link=http://zldncrggzjjn.com/]zldncrggzjjn[/link], http://dqulctzepdzu.com/

Posted By: bdaocqk On: 11/28/11 12:27 PM

Thanks. I now know more about application security

Posted By: Best quality watches On: 12/02/11 9:57 AM

Among those posts I've seen, this is the most particular one, and I think the blogger must have spent lots of time on it, thank you so much!

Posted By: Home Security Houston On: 12/18/11 3:11 AM

I read this post, Good blog for youngsters, because his take quality free knowledge on internet, thanks for wonderful sharing,

Posted By: dissertation writing On: 12/22/11 12:48 AM

Every article you wrote brilliant among the blog users! No surprise you got a lot of comments on this post.

Posted By: Literature Review Example On: 12/24/11 12:24 AM

There are many reasons to further your education. Sadly, many people allow the business of their lives to keep them away from ever doing so. If you have had that itch to get back to school to further your education and want to once again start hitting the books, then you might want to consider going after an online degree.

Posted By: Law Essay On: 01/21/12 12:08 AM

Add Comment

Comments have been closed.

Transcript

no image

Slide Text

Slide Notes


Twin Cities ColdFusion User Group Intro to Application Security

no text exists for this slide

no notes exist for this slide

Who am I

no text exists for this slide

no notes exist for this slide

What is Application Security

no text exists for this slide

no notes exist for this slide

How do I know if my application is secure

no text exists for this slide

no notes exist for this slide

So how do I make my application secure

no text exists for this slide

no notes exist for this slide

Determine assets

no text exists for this slide

no notes exist for this slide

Understand the Threats

no text exists for this slide

no notes exist for this slide

Discover Vulnerabilities

no text exists for this slide

no notes exist for this slide

Attack your Application

no text exists for this slide

no notes exist for this slide

Create Countermeasures

no text exists for this slide

no notes exist for this slide

So W hat are our Assets

no text exists for this slide

no notes exist for this slide

What are the threatsattacks

no text exists for this slide

no notes exist for this slide

What are we going to talk about

no text exists for this slide

no notes exist for this slide

The Less Obvious Threats Ignorance Assumptions and Laziness

no text exists for this slide

no notes exist for this slide

Ignorance

no text exists for this slide

no notes exist for this slide

Assumptions

no text exists for this slide

no notes exist for this slide

Assumptions about users

no text exists for this slide

no notes exist for this slide

Assumptions about Hacker Interest

no text exists for this slide

no notes exist for this slide

Assumptions about how your application will be used

no text exists for this slide

no notes exist for this slide

Assumptions about how your application will be used cont

no text exists for this slide

no notes exist for this slide

Assumptions about administratorhost

no text exists for this slide

no notes exist for this slide

Assumptions about how the serverenvironment work

no text exists for this slide

no notes exist for this slide

Laziness

no text exists for this slide

no notes exist for this slide

The Basic Threats

no text exists for this slide

no notes exist for this slide

SQL Injection

no text exists for this slide

no notes exist for this slide

SQL Injection Examples

no text exists for this slide

no notes exist for this slide

SQL Injection Examples cont

no text exists for this slide

no notes exist for this slide

Slide 28

no text exists for this slide

no notes exist for this slide

Slide 29

no text exists for this slide

no notes exist for this slide

Slide 30

no text exists for this slide

no notes exist for this slide

How do we stop SQL Injection attacks

no text exists for this slide

no notes exist for this slide

SQL Injection Example cont

no text exists for this slide

no notes exist for this slide

ltcfqueryparamgt in use

no text exists for this slide

no notes exist for this slide

What about other Dynamic Elements in SQL

no text exists for this slide

no notes exist for this slide

CrossSite Scripting XSS

no text exists for this slide

no notes exist for this slide

Slide 36

no text exists for this slide

no notes exist for this slide

XSS Example

no text exists for this slide

no notes exist for this slide

Slide 38

no text exists for this slide

no notes exist for this slide

XSS Uses

no text exists for this slide

no notes exist for this slide

XSS iFrame Example

no text exists for this slide

no notes exist for this slide

XSS Prevention

no text exists for this slide

no notes exist for this slide

ColdFusion Script Protect

no text exists for this slide

no notes exist for this slide

HTMLEditFormat Function

no text exists for this slide

no notes exist for this slide

Input Validation

no text exists for this slide

no notes exist for this slide

Cookie Security

no text exists for this slide

no notes exist for this slide

Slide 46

no text exists for this slide

no notes exist for this slide

Slide 47

no text exists for this slide

no notes exist for this slide

Slide 48

no text exists for this slide

no notes exist for this slide

Questions

no text exists for this slide

no notes exist for this slide

Resources

no text exists for this slide

no notes exist for this slide