Content-Security-Policy: An Introduction

แชร์
ฝัง
  • เผยแพร่เมื่อ 23 ก.ค. 2024
  • Content-Security-Policy (CSP) is a major control to protect against Cross-Site Scripting Attacks. This video talks about both offensive and defensive perspectives of Content-Security-Policy implementations for your application
    For more such content, subscribe to my channel dedicated to security:
    / appsecengineer
  • วิทยาศาสตร์และเทคโนโลยี

ความคิดเห็น • 47

  • @codedynamics1
    @codedynamics1 2 ปีที่แล้ว +2

    I found this video a while ago and saved it. This fundemental for websites and web applications to mitigate XSS attacks. I came across a 'trusted scripts assignment' error in the console and after a ton of research i've started implementing a CSP header (you can also use the meta tag to set a CSP) but i still needed more info so i came back here. Thanks for taking time to make this video Abhay i can see that you've gone through some lengths to hide personal info before uploading the video so its really appreciated and its going to help alot.

  • @ramanjha2277
    @ramanjha2277 ปีที่แล้ว +3

    This is one of the best videos I have ever seen on any topic.

  • @goodthoughtwelike
    @goodthoughtwelike 4 ปีที่แล้ว +4

    Abhay, this is one of the best presentations. This whole video is able to maintain the curiosity. Thanks a lot.

    • @abhaybhargav
      @abhaybhargav  4 ปีที่แล้ว

      Thank you very much for your compliments :)

  • @ellaiyarasankalidass5267
    @ellaiyarasankalidass5267 2 ปีที่แล้ว +2

    Great content, learnt valuable lesson from you as a web developer.

  • @GaneshPrabhuRajendran
    @GaneshPrabhuRajendran 3 หลายเดือนก่อน

    This is best video for learning CSP

  • @hitnahsin
    @hitnahsin 4 ปีที่แล้ว +1

    Thanks for the information , explanation and your time !!!

  • @kobicohen3205
    @kobicohen3205 3 ปีที่แล้ว

    great explanation... good luck Abhay

  • @aravindgop1
    @aravindgop1 4 ปีที่แล้ว +4

    It was a very professional presentation.. I especially liked the courtesy links that you have posted towards the end ... 👍🏻

  • @ajayKumar-yc4mf
    @ajayKumar-yc4mf ปีที่แล้ว

    Very Well explained, the details you go into are very helpful

  • @sandeepdantuluri3414
    @sandeepdantuluri3414 5 ปีที่แล้ว +4

    Great n unique way of explanation sir.
    Waiting to learn more concepts 👌👌

  • @olenaback1212
    @olenaback1212 3 ปีที่แล้ว +2

    This is a very perspicuous explanation/ intro into CSP! Thanks!

  • @AmanMankar
    @AmanMankar 3 ปีที่แล้ว

    Hey Ashish, quick question. if I have 'connect-src *' but have explicitly limited script-src and all other derivatives to a particular domain, how much of a threat is it?

  •  3 ปีที่แล้ว

    You explained it very well. Concept is clear to me. But how do I get my javascript loaded without errors. I have very little knowledge of Java and have played with a bit. I found which files causing the errors but how do I correct this. Where do I inject the nonce or hash code in my files or remove the errors in my javascrips?

  • @_justinprojects
    @_justinprojects 5 หลายเดือนก่อน

    very thorough, thanks for the demo!

  • @johnybandlamudi1838
    @johnybandlamudi1838 4 ปีที่แล้ว +1

    Thank you for the detailed explanation.

  • @dougthefiddler
    @dougthefiddler 3 ปีที่แล้ว +1

    Awesome information - really clear - thanks!

  • @shikharjoshi267
    @shikharjoshi267 3 ปีที่แล้ว +2

    This video is gold.

  • @GopalSinghR1
    @GopalSinghR1 ปีที่แล้ว

    Excellent Explanation

  • @ritiksahni542
    @ritiksahni542 3 ปีที่แล้ว +1

    A great presentation! Loved it.

  • @antonyshaji2008
    @antonyshaji2008 ปีที่แล้ว

    Much appreciated. thanks.

  • @robl39
    @robl39 3 ปีที่แล้ว +1

    I finally get it. Thanks!

    • @abhaybhargav
      @abhaybhargav  3 ปีที่แล้ว

      Glad you found it useful

  • @domaincontroller
    @domaincontroller 3 ปีที่แล้ว

    07:37 set by the (Application) server 08:19 my web server would indicate to the browser via an HTTP header, from the same origin server

  • @sundargeek4915
    @sundargeek4915 4 ปีที่แล้ว +5

    Dude, This is good

  • @subhadharshini9303
    @subhadharshini9303 4 ปีที่แล้ว

    presentation was very neat and good. Very much helpful

  • @samuelbotini8547
    @samuelbotini8547 3 ปีที่แล้ว

    wow bro it's an awesome explanation, tanks for this, and your english pronunciation it's amazing

  • @AmarSingh-uw1db
    @AmarSingh-uw1db 4 ปีที่แล้ว +1

    Awsome, explanation sir great 👍

  • @alucardjp1
    @alucardjp1 4 ปีที่แล้ว +1

    Great video

  • @TheBikerr
    @TheBikerr 3 วันที่ผ่านมา

    Very informative Video, One request please share link to the source code of the application...

  • @venkateswarareddy5137
    @venkateswarareddy5137 4 ปีที่แล้ว

    Nice Presentation!

  • @jeganofsathyabama
    @jeganofsathyabama 3 ปีที่แล้ว

    Willing to talk to you around some appsec problems that i want to solve for my company.
    Kindly accept my invite on LinkedIn