"Alice, Bob, Eve and Trent"
My Hacker Hour talk on Cyber Security - given at Rutgers University for USACS!
- Authentication vs Identification vs Authorization
- Security Model (Alice, Bob, Eve and Trent)
- Prevention, detection, recovery cycle
- Passwords
- Salting Passwords
- MS-CHAP protocol
- Man in the Middle Attacks
- Using a signed message to prevent MITM Attack
- Timestamps to prevent replay Attacks
- SSL Certificate/CA Overview
- Browser Security
- What's possible?
- Cookies and XSRF in Browsers
- How are XSRF attacks caused, possible damage
- Using a
referrerheader in a cookie to defend against XSRF
- JWT (JSON Web Tokens) for authentication, encryption and signing
- OAuth 2.0
- XSS attacks
- Demo: GAH. Use the chat function and inject JS between <script> tags!
- Defenses: OWASP Guidelines, Content Security Policy
- OWASP Guidelines
- SQL Injection
- Demo: Hackable
- Using prepared statements (parameterized values), database permissions and escape functions to avoid passing SQL Methods to execute.