Sveriges mest populära poddar
The Application Security Podcast
The Application Security Podcast

Jim Manico -- The Extremely Unabridged History of SQLi and XSS

30 min3 december 2018

Om avsnittet

Why are SQL injection and cross-site scripting still with us after years of knowing how to prevent them? Jim Manico joins Chris for an informal journey through the history of both vulnerability classes and the defenses that changed application development. They discuss parameterized database APIs, output encoding, sanitization, framework defaults, and the long life of legacy software. The conversation then turns toward the future: what security libraries and language-specific analysis can do, where commercial testing tools fit, and who has an incentive to invest in stronger platforms. Jim’s recollections and predictions make this an opinionated archive conversation about progress and persistence, with a central challenge for developers and security teams: make protection a normal part of building software.

The Application Security Podcast is brought to you by Security Journey.

About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
Learn more about Security Journey

Connect with Jim Manico:
Jim Manico on LinkedIn

Mentioned in this episode:
DOMPurify
OWASP ESAPI
Go html/template
Brakeman
OWASP Top 10

Follow the Application Security Podcast:
Home
X
LinkedIn
YouTube
Instagram
➜ Facebook

Chapters:
00:00 The history of SQL injection and XSS with Jim Manico
01:33 How application security has changed
05:06 Parameterized queries and early defenses
07:20 Why injection remains on the Top 10
09:22 Could SQL injection disappear?
10:39 Tracing the history of cross-site scripting
17:21 Carrying secure defaults into new frameworks
19:34 Legacy applications and long software lifespans
20:47 The role of defensive technology
23:13 What happens to the security tool market?
24:52 Why language-specific analysis matters
26:26 Who pays for more secure platforms?

The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.