Brian Dukes
Work at Engage Software, developing websites on the DNN Platform (a DNN MVP). I also serve Jesus at City Lights Church.
Download the DNN Summit Mobile App now and take the survey at the end of the conference to be entered to win a $100 Amazon gift card!
TOP
to limit disclosure
XmlTextWriter
.git
) aren't in web rootSee OWASP Secure Headers Project
AntiXssEncoder
eval
can cause code executionEvery organization must ensure that there is an ongoing plan for monitoring, triaging, and applying updates or configuration changes for the lifetime of the application or portfolio.
https://www.owasp.org/index.php/Category:OWASP_Top_Ten_2017_Project
https://cwe.mitre.org/
By Brian Dukes
It can be hard to keep up-to-date on the latest best practices for web security, as well as to understand how they affect a shared environment like DNN. As our development approaches change to take web services into account, we need to adjust our security practices to continue protecting our clients and users. This presentation will review a number of practices that you can undertake to increase the security of your web application, highlighting common errors in applications as well as newer vulnerabilities that have come to light.
Work at Engage Software, developing websites on the DNN Platform (a DNN MVP). I also serve Jesus at City Lights Church.