Web application attacks: Building hardened apps

Intrusion Defense School

Web application attacks: Building hardened apps

Most enterprises rely on swift development of Web applications that meet project deadlines and bring in new revenue. In order to succeed, Web app development processes often focus on features and functionality, ignoring security until it's too late. Thorough testing for vulnerabilities in Web applications is often bypassed, leaving sensitive data on the back end subject to attack.

This lesson details the myriad of Web application attacks in circulation today, providing detailed explanations of SQL injection attacks, clickjacking, cross-site scripting and cross-site request forgery attacks and other Web-based attacks that lead right to sensitive information stored in a backend database. We’ll also explain how to begin assessing your production Web apps for dangerous flaws and how to architect a software development process that can help you counter these threats in both QA and production.

About the expert:

Cory Scott is a director with security consultancy Matasano Security.