About this talk
This talk focuses on web application security, highlighting best practices to safeguard sites while adopting an attacker's perspective to understand exploitation techniques. The speaker discusses common pitfalls that Drupal developers encounter, including XSS, CSRF, access bypass, SQL injection, and denial of service attacks, and offers strategies to circumvent these issues. With extensive experience as part of the security team and code review administrators on drupal.org, the speaker shares insights on secure configuration practices and essential tools and modules to enhance site security. While the session primarily features examples from Drupal core versions 7.x and 8.x, the principles discussed are applicable to all PHP web applications, including new security improvements in Drupal 8, such as auto-escaping with the Twig template engine for XSS prevention and built-in CSRF token support.
More from this event
See all 144 talks →
DrupalCon Dublin 2016: About Your DrupalCon Dublin Sponsorship
59:56
DrupalCon Dublin 2016: Keynote - Driesnote
1:29:47
DrupalCon Dublin 2016: PRENOTE - IS THE POT OF GOLD IN SCOPE?
33:28
DrupalCon Dublin 2016: Drupal 8's Multilingual APIs: Building for the Entire World
48:38