DrupalCon Dublin 2016: Cracking Drupal

52:23 · 26 Sep 2016 – 30 Sep 2016 · YouTube

About this talk

This talk focuses on web application security, highlighting best practices to safeguard sites while adopting an attacker's perspective to understand exploitation techniques. The speaker discusses common pitfalls that Drupal developers encounter, including XSS, CSRF, access bypass, SQL injection, and denial of service attacks, and offers strategies to circumvent these issues. With extensive experience as part of the security team and code review administrators on drupal.org, the speaker shares insights on secure configuration practices and essential tools and modules to enhance site security. While the session primarily features examples from Drupal core versions 7.x and 8.x, the principles discussed are applicable to all PHP web applications, including new security improvements in Drupal 8, such as auto-escaping with the Twig template engine for XSS prevention and built-in CSRF token support.

From event

DrupalCon Dublin 2016

26 Sep 2016 – 30 Sep 2016

All event videos
Back to Watch