141: Web Application Security, Part 2 with Scott Arciszewski

Published: Jan. 19, 2018, 2:15 p.m.

In this weeks episode we continue our discussion with Scott Arciszewski about all things Security and Cryptography.\nWe start off the show by highlighting what a SQL injection attack is and the differences between (emulated) prepared statements.\nThis leads us on to look into how to securely handle file uploads, what a reverse shell is and how to defend yourself against XSS/CSRF attacks.\nFrom here we touch upon the recent inclusion of libsodium into PHP, why mcrypt should be avoided, and the side-channel vulnerabilities that brought way to Meltdown and Spectre.\nFinally, we mention how computers generate seemingly random numbers, what a Web Application Firewall (WAF) is, and how WARD goes about protecting your systems.