Hacking Your Website with Troy Hunt
Carl and Richard talk to Troy Hunt about hacking yourself - testing your web site's defenses before someone else does! The conversation starts out talking about FireSheep and the need to use SSL everywhere. If you log in, you should be using SSL! Troy runs down a list of the common exploits you should test against, like SQL injection and cookie spoofing. There's also a discussion around cross-site scripting and X-Frame-Options. There are some simple things that script kiddies can do to exploit your site - you should do them first, and then defend yourself!
Guests:
Troy Hunt
Troy Hunt is a Pluralsight author, Microsoft Regional Director and MVP and a world-renowned internet security specialist. He spends his time travelling the world speaking and running workshops where he teaches developers how to break into their own systems before helping to piece them back together to be secure against today’s online threats. He’s also the creator of “Have I been pwned?”, the free online service for breach monitoring and notifications. Troy regularly blogs at troyhunt.com from his home on the Gold Coast in Australia.
Links:
- ASP.NET Identity http://www.asp.net/visual-studio/overview/2013/release-notes-(release-candidate)#TOC8
- Troy's Web Site http://www.troyhunt.com/
- FireSheep http://codebutler.com/firesheep/
- StartSSL http://www.startssl.com/
- XKCD on SQL Injection http://xkcd.com/327/
- Browser Exploitation Framework Project http://beefproject.com/
- Combating ClickJacking with X-Frame-Options http://blogs.msdn.com/b/ieinternals/archive/2010/03/30/combating-clickjacking-with-x-frame-options.aspx
- Troy's Pluralsight Class on Hacking Yourself http://pluralsight.com/training/Courses/TableOfContents/hack-yourself-first
- Free EBook: OWASP Top 10 for .NET Developers http://www.troyhunt.com/2011/12/free-ebook-owasp-top-10-for-net.html
- Havij http://www.itsecteam.com/products/havij-v116-advanced-sql-injection/
- XSS Filter Evasion Cheat Sheet https://www.owasp.org/index.php/XSS_Filter_Evasion_Cheat_Sheet
- Troy Hunt Scams the Scammer http://www.youtube.com/watch?v=kjKjyMKj3n4
- WiFi Pineapple https://wifipineapple.com/