Bad Web Applications: Security Architecture and Pen Testing Horrors

No ratings

Presented at BSidesBristol 2019 by

As a Security Architect and Pen Tester, I see a lot of designs for and implementations of Web Applications, and all too many have flaws which render them unfit to hold the data entrusted to them. Web Application breaches are reported almost weekly, and while victim organisations may claim they have suffered an “unprecedented sophisticated cyber-attack” that is rarely the case. GDPR makes “data protection by design” a legal requirement, and breaches due to badly designed, configured and maintained applications are likely to lead to heavy fines. This presentation will draw on the experience of reviewing application designs, and pen tests of developed applications to highlight the avoidable horrors which may be hiding behind a funky front-end. Audience participation will be encouraged, as I’m sure I don’t have the monopoly on interesting examples and mitigation options. This session is for anyone with an interest in Web App security, from developers to business stakeholders and the merely curious.