2017 OWASP Top 10: Sensitive Data Exposure

แชร์
ฝัง
  • เผยแพร่เมื่อ 4 พ.ย. 2024

ความคิดเห็น • 54

  • @Zeeshan220dtsi
    @Zeeshan220dtsi 4 ปีที่แล้ว +7

    It couldn't get more simple than this !!! Good Job

    • @devcentral
      @devcentral  4 ปีที่แล้ว +1

      glad you enjoyed it!

  • @MaffBowers
    @MaffBowers 5 ปีที่แล้ว +14

    These OWASP tutorials are fantastic. Thank you for your efforts.

    • @devcentral
      @devcentral  5 ปีที่แล้ว +2

      glad you enjoy them!

    • @kadejaxx701
      @kadejaxx701 3 ปีที่แล้ว

      I dont mean to be so offtopic but does anyone know a way to get back into an instagram account?
      I was stupid lost my password. I would appreciate any help you can offer me

  • @sreeharisanjeev8271
    @sreeharisanjeev8271 4 ปีที่แล้ว +12

    Thank you so much for the series

    • @devcentral
      @devcentral  4 ปีที่แล้ว +3

      I'm glad you enjoy the videos!

  • @NileshYadav-ps8qe
    @NileshYadav-ps8qe 6 ปีที่แล้ว +5

    I like the way you keep things simple while explaining very good videos Thank You !!

    • @devcentral
      @devcentral  6 ปีที่แล้ว

      glad you find these videos helpful!

  • @mohamedaslam8918
    @mohamedaslam8918 4 ปีที่แล้ว +2

    Wow awesome explanation,
    Going to watch all the episodes

    • @devcentral
      @devcentral  4 ปีที่แล้ว

      glad you enjoyed it!

  • @frankthabo
    @frankthabo 3 ปีที่แล้ว +1

    Kudos on the presentation --

    • @devcentral
      @devcentral  3 ปีที่แล้ว

      Glad you enjoyed it!

  • @sarikarai7029
    @sarikarai7029 2 ปีที่แล้ว +1

    thanks for explaining these topics but can you also explain owasp top 10 2021?

    • @devcentral
      @devcentral  2 ปีที่แล้ว +1

      John is working on an updated series for the OWASP Top 10 2021. Stay tuned! :-)

    • @sarikarai7029
      @sarikarai7029 2 ปีที่แล้ว +1

      @@devcentral thanks for update

  • @AbhishekToney
    @AbhishekToney 6 ปีที่แล้ว +8

    Thank-you all these videos are really helpful to me :)

    • @devcentral
      @devcentral  6 ปีที่แล้ว

      glad you are enjoying them!

  • @sunilshah7358
    @sunilshah7358 6 ปีที่แล้ว +3

    John! I'm a fan! thanks a ton for these videos!

    • @devcentral
      @devcentral  6 ปีที่แล้ว

      glad you enjoy these videos!

  • @72dilara
    @72dilara 3 ปีที่แล้ว +2

    How do you crack the encryption with rainbow table @5.04 ???

    • @devcentral
      @devcentral  3 ปีที่แล้ว +1

      Great question! User passwords are typically stored as hash values...not the actual password itself. A hash algorithm is run against the password and the hash value is stored and used to allow access or not. A rainbow table takes a list of common passwords and runs them through a variety of hashing algorithms and then that output (the hashes) can be used to try and gain access to the system. This is one reason to use strong, not-easily-guessed passwords! I hope this helps!

  • @stillunknown5785
    @stillunknown5785 3 ปีที่แล้ว +1

    Great explanation sir

  • @Rookey_Traveller
    @Rookey_Traveller 4 ปีที่แล้ว +1

    Hi there, can I consider web server type or version as sensitive data? Framework used ?

  • @carina_lins
    @carina_lins 5 ปีที่แล้ว +4

    Best explanation so far! Thank you so much, helped me a lot to clarify :)

    • @devcentral
      @devcentral  5 ปีที่แล้ว

      glad you enjoyed it!

  • @abhaypratap5311
    @abhaypratap5311 5 ปีที่แล้ว +1

    What about when encrypted data in the form of "IN use " and "iN Transmission" then how to detect exfiltration specially in Https

    • @brakish3938
      @brakish3938 3 ปีที่แล้ว

      Siem or ids can help in this case I guess.

  • @pramitkarmakar6692
    @pramitkarmakar6692 6 ปีที่แล้ว +2

    What kind of a board are u using?? writing in the front, I didn't get that...

    • @devcentral
      @devcentral  6 ปีที่แล้ว +1

      Here's a "behind the scenes" look at how we film these lightboard lessons: devcentral.f5.com/articles/lightboard-lessons-behind-the-scenes

    • @pramitkarmakar6692
      @pramitkarmakar6692 6 ปีที่แล้ว +2

      @@devcentral So that's how its done... Nice 👍

    • @MaffBowers
      @MaffBowers 5 ปีที่แล้ว

      @@devcentral It does look like you can write backwards incredibly well! Flipping the image in post makes much more sense though! :)

  • @Luisa2ballRS
    @Luisa2ballRS 6 ปีที่แล้ว +1

    Could anyone explain what are ciphers? I'm not sure I understand what he means by "strong ciphers"

    • @devcentral
      @devcentral  6 ปีที่แล้ว

      This article on DevCentral should be helpful: devcentral.f5.com/articles/cipher-suite-practices-and-pitfalls-25564

    • @Luisa2ballRS
      @Luisa2ballRS 6 ปีที่แล้ว +1

      Thank you!

    • @joshwaphilip9840
      @joshwaphilip9840 5 ปีที่แล้ว +2

      cipher is an algorithm for encrypting and decrypting data. example modern web application use TLS 1.3 encryption method for network connection.

  • @mandy2533
    @mandy2533 3 ปีที่แล้ว +2

    Thank you!!!

  • @sonnygrover5277
    @sonnygrover5277 5 ปีที่แล้ว +2

    Sooper Video - explanation

    • @devcentral
      @devcentral  5 ปีที่แล้ว

      glad you enjoyed it!

  • @rajanisagale5554
    @rajanisagale5554 5 ปีที่แล้ว +1

    very well explained... goood

    • @devcentral
      @devcentral  5 ปีที่แล้ว

      glad you enjoyed it!

  • @bigmarkua
    @bigmarkua 4 ปีที่แล้ว +2

    Thanks :)

  • @FleurOlivia
    @FleurOlivia 6 ปีที่แล้ว +1

    Thank you!

    • @devcentral
      @devcentral  6 ปีที่แล้ว

      glad you enjoyed it!

  • @fadlymahendra
    @fadlymahendra 5 ปีที่แล้ว +1

    "If possible, don't store sensitive data", could you give me the example how it should be?

    • @devcentral
      @devcentral  5 ปีที่แล้ว +1

      This depends on your specific web application, but sometimes people will store sensitive data even if they don't have to. The idea here is that you should keep only the data that you absolutely have to in order to do the job. If there is any data that you can discard then you should discard it...delete it (maybe a user submits an address or something but you don't need that information for your web application to work properly).

    • @mit9191
      @mit9191 4 ปีที่แล้ว

      As an example, if you are building a payment processor app and you are using third party services as a Payment Gateway, directly introduce an in user's browser which will point to payment gateway where user will feed card data and your app will neither have that credit card data in transit or at rest.

  • @theskipper1867
    @theskipper1867 ปีที่แล้ว +1

    Ok. This drives me nuts. Are you writing backwards? If so how???
    It's literally the only thing I can think about while watching these.

    • @devcentral
      @devcentral  ปีที่แล้ว +1

      Thanks for the comment! Here's how we produce these: th-cam.com/video/U7E_L4wCPTc/w-d-xo.html

    • @theskipper1867
      @theskipper1867 ปีที่แล้ว +1

      @@devcentral thanks! This assuages my curiosity.

  • @phealy02
    @phealy02 2 ปีที่แล้ว +1

    I could never write backwards like that, and he's not even Chinese! 🤔

    • @psilvas
      @psilvas 2 ปีที่แล้ว

      How we do it: th-cam.com/video/U7E_L4wCPTc/w-d-xo.html