SlideShare a Scribd company logo
1 of 7
SO LET’S TALK ABOUT SECURITY
the Security Factory – Stijn Jans – stijn.jans@thesecurityfactory.be
Injection
Session hijacking
Cross-Site Scripting (XSS)
Insecure Direct Object References
Security Misconfiguration
Sensitive Data Exposure
Functional Level Access Control
Cross-Site Request Forgery (CSRF)
Using Known Vulnerable Components
Unvalidated Redirects and Forwards
www.cronos.be

More Related Content

Viewers also liked

Adj agree ppt
Adj agree pptAdj agree ppt
Adj agree ppt
roqued
 
Budgeting and presentations
Budgeting and presentationsBudgeting and presentations
Budgeting and presentations
roqued
 

Viewers also liked (7)

Going Mobile at a Glance - How is my app doing?
Going Mobile at a Glance - How is my app doing?Going Mobile at a Glance - How is my app doing?
Going Mobile at a Glance - How is my app doing?
 
Adj agree ppt
Adj agree pptAdj agree ppt
Adj agree ppt
 
Budgeting and presentations
Budgeting and presentationsBudgeting and presentations
Budgeting and presentations
 
Going Mobile at a Glance - Manage your devices
Going Mobile at a Glance - Manage your devicesGoing Mobile at a Glance - Manage your devices
Going Mobile at a Glance - Manage your devices
 
Rapporting with nlp
Rapporting with nlpRapporting with nlp
Rapporting with nlp
 
Giới thiệu về viện đào tạo NLP Tâm Thức Mới (Newmind NLP Academy)
Giới thiệu về viện đào tạo NLP Tâm Thức Mới (Newmind NLP Academy)Giới thiệu về viện đào tạo NLP Tâm Thức Mới (Newmind NLP Academy)
Giới thiệu về viện đào tạo NLP Tâm Thức Mới (Newmind NLP Academy)
 
SAPTECHED 2016 EMEA - 10 Golden Rules for Designing a Custom-Built SAP Fiori...
SAPTECHED 2016  EMEA - 10 Golden Rules for Designing a Custom-Built SAP Fiori...SAPTECHED 2016  EMEA - 10 Golden Rules for Designing a Custom-Built SAP Fiori...
SAPTECHED 2016 EMEA - 10 Golden Rules for Designing a Custom-Built SAP Fiori...
 

More from Cronos Mobile (6)

Cronos mobilei3
Cronos mobilei3Cronos mobilei3
Cronos mobilei3
 
Mobilize the Enterprise - Why ux matters
Mobilize the Enterprise - Why ux mattersMobilize the Enterprise - Why ux matters
Mobilize the Enterprise - Why ux matters
 
Mobilize the enterprise - What can we do for you ?
Mobilize the enterprise - What can we do for you ?Mobilize the enterprise - What can we do for you ?
Mobilize the enterprise - What can we do for you ?
 
Mobilize the Enterprise - Development approach : is there a Holy Grail ?
Mobilize the Enterprise - Development approach : is there a Holy Grail ?Mobilize the Enterprise - Development approach : is there a Holy Grail ?
Mobilize the Enterprise - Development approach : is there a Holy Grail ?
 
Mobile at a Glance - A user centered approach for better ROI
Mobile at a Glance - A user centered approach for better ROIMobile at a Glance - A user centered approach for better ROI
Mobile at a Glance - A user centered approach for better ROI
 
Going Mobile at a Glance - Do you need to build from scratch?
Going Mobile at a Glance - Do you need to build from scratch?Going Mobile at a Glance - Do you need to build from scratch?
Going Mobile at a Glance - Do you need to build from scratch?
 

Recently uploaded

Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Victor Rentea
 

Recently uploaded (20)

Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...
 
MS Copilot expands with MS Graph connectors
MS Copilot expands with MS Graph connectorsMS Copilot expands with MS Graph connectors
MS Copilot expands with MS Graph connectors
 
DBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor PresentationDBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor Presentation
 
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
 
Exploring Multimodal Embeddings with Milvus
Exploring Multimodal Embeddings with MilvusExploring Multimodal Embeddings with Milvus
Exploring Multimodal Embeddings with Milvus
 
Manulife - Insurer Transformation Award 2024
Manulife - Insurer Transformation Award 2024Manulife - Insurer Transformation Award 2024
Manulife - Insurer Transformation Award 2024
 
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
 
CNIC Information System with Pakdata Cf In Pakistan
CNIC Information System with Pakdata Cf In PakistanCNIC Information System with Pakdata Cf In Pakistan
CNIC Information System with Pakdata Cf In Pakistan
 
ICT role in 21st century education and its challenges
ICT role in 21st century education and its challengesICT role in 21st century education and its challenges
ICT role in 21st century education and its challenges
 
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...
 
AWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of Terraform
 
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWEREMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024
 
Ransomware_Q4_2023. The report. [EN].pdf
Ransomware_Q4_2023. The report. [EN].pdfRansomware_Q4_2023. The report. [EN].pdf
Ransomware_Q4_2023. The report. [EN].pdf
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data DiscoveryTrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
 
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ..."I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...
 
Artificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : UncertaintyArtificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : Uncertainty
 
FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024
 

Going Mobile at a Glance - What about security

  • 1.
  • 2. SO LET’S TALK ABOUT SECURITY the Security Factory – Stijn Jans – stijn.jans@thesecurityfactory.be
  • 3.
  • 4.
  • 5. Injection Session hijacking Cross-Site Scripting (XSS) Insecure Direct Object References Security Misconfiguration Sensitive Data Exposure Functional Level Access Control Cross-Site Request Forgery (CSRF) Using Known Vulnerable Components Unvalidated Redirects and Forwards
  • 6.