Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

Fixing XSS with Content Security Policy

LASCON via YouTube

Overview

This course aims to teach learners how to mitigate cross-site scripting (XSS) attacks using Content Security Policy (CSP). The learning outcomes include understanding the differences between CSP 1.0 and CSP 2.0, learning how CSP protects web applications from XSS, and knowing how to implement CSP on a website. The course covers topics such as DOM-based XSS, script sources, wildcards, default CSP, connecting sources, monitoring, report-only policy, inline JavaScript, CSP nonce, and hash sources. The teaching method involves a 30-minute talk by a Senior Security Consultant, making it suitable for web application developers interested in enhancing their security measures.

Syllabus

Intro
About Ksenia
Dombased XSS
Script source
Wildcards
Default
CSS
Connect Source
Monitoring
Report Only Policy
Inline JavaScript
CSP
Nonce
Hash Source

Taught by

LASCON

Reviews

Start your review of Fixing XSS with Content Security Policy

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.