Sveriges mest populära poddar
The Application Security Podcast
The Application Security Podcast

Niels Tanis -- A Slice of the Razor with ASP.Net Core

29 min11 september 2018

Om avsnittet

Framework defaults can prevent common vulnerabilities, but developers still need to understand when their code bypasses those protections. Niels Tanis joins the podcast at AppSecEU to unpack ASP.NET Core and Razor Pages from a security perspective. He explains the framework’s structure, dependency and package concerns, and the protections around request forgery and output encoding. The conversation explores why rendering raw HTML deserves scrutiny, how validation and model state work, and how overposting can expose fields that never appear in the interface. Niels also discusses tooling and ways to begin learning the platform. This archive episode gives .NET developers a practical way to reason about what the framework does for them and which responsibilities remain in their application code.

The Application Security Podcast is brought to you by Security Journey.

About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
Learn more about Security Journey

Connect with Niels Tanis:
Niels Tanis on LinkedIn

Mentioned in this episode:
ASP.NET Core Razor Pages documentation
ASP.NET Core documentation
NuGet
Scott Hanselman on overposting and mass assignment

Follow the Application Security Podcast:
Home
X
LinkedIn
YouTube
Instagram
➜ Facebook

Chapters:
00:00 ASP.NET Core and Razor security with Niels Tanis
01:25 Niels’s security origin story
03:44 The security implications of a changing .NET platform
05:57 Understanding ASP.NET Core and MVC
07:54 Framework and dependency challenges
12:41 Razor Pages and security defaults
14:16 Baseline protections and output encoding
16:16 Why raw HTML deserves extra review
17:26 Explicitly overriding secure defaults
19:52 Security tooling through NuGet
20:24 Input validation and model state
21:55 Overposting and mass assignment
26:23 Where new .NET developers can learn more

The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.