Stephen Rees-Carter "Th1nk Lik3 a H4cker" - Laracon US 2023 Nashville

Поділитися
Вставка
  • Опубліковано 18 жов 2024

КОМЕНТАРІ • 15

  • @0zankurt
    @0zankurt Рік тому +2

    Can we have access to that command line tool?

  • @_whatistruth
    @_whatistruth Рік тому +2

    that was great! learned a lot of new things

  • @HORKimhab
    @HORKimhab Рік тому

    Could please tell me how to use dropbear laravel?

  • @1234matthewjohnson
    @1234matthewjohnson Рік тому +1

    Great talk

  • @namumakwembo
    @namumakwembo Рік тому +3

    hahaha this guy got the whole room quiet , lol awesome though he is really really good

  • @martinbean
    @martinbean Рік тому +4

    I see the correct password has been edited 😂

    • @alexhackney4045
      @alexhackney4045 Рік тому

      How can you tell? lol

    • @martinbean
      @martinbean Рік тому

      @@alexhackney4045 I was there, and that’s _not_ the “correct” password that was chosen at the time.

  • @SodalisUK
    @SodalisUK Рік тому +1

    Laravel needs to have some tests that you can call which check for these security things, and improved middle-age to stop these things from working!!

    • @Ruggie1of1
      @Ruggie1of1 Рік тому +2

      Laravel doesn't do these things by default, the vulnerabilities displayed were intentionally coded to demonstrate mistakes developers make without noticing. If you take away anything from this talk, it should be: 1. Always use policies (these are testable) 2. Sanitize user input, even from the route URL (maybe also 3. Don't load files based on strings provided by a user)

    • @SodalisUK
      @SodalisUK Рік тому +1

      @@Ruggie1of1 Yes, but these things are also testable and standard tests would ensure that the user hasn't made these mistakes.

  • @CharlesHassekf
    @CharlesHassekf Рік тому

    I think the speaker should train his breathing and take it slow. This seems like a "end of the game" interview with so much panting.

  • @mayanksgajjar
    @mayanksgajjar Рік тому

    LOL I can hack the Laravel sites now