Cary Hooper (@nopantrootdance) presents "Modern Web Application Vulnerabilities (on the perimeter right now)"
Attend this presentation and walk away with an increased awareness of lingering attack surface on organization perimeters. Though some customer's only interface is in brick and mortar service centers, more and more, web and mobile applications are quickly becoming the norm for customer interactions. This experience comes with an inherent expectation that an institution will protect its data, users, and assets in cyberspace. This presentation discusses and demonstrates three classes of modern web application misconfigurations and vulnerabilities widely present on network perimeters today. First, it studies specific vulnerabilities in modern front-end frameworks such as AngularJS. Next, it examines vulnerabilities in PDF generation from untrusted HTML. Last, it argues the importance of HTTPS everywhere and implementing proper HTTP Strict-Transport-Security directives to significantly degrade man-in-the-middle attacks.