A holistic view of how the web works, with an overview of the HTTP protocol.
Presented by me at null security group (http://null.co.in), Mumbai chapter meet on Aug' 27th.
Browser APIs for data exchange: types and applicationPavel Klimiankou
What browser APIs can we use for data exchange. XMLHttpRequest, fetch(), Server-Sent Events, WebSocket, WebRTC. What's the difference. Use cases for each of those.
Mobile applications Development - Lecture 17
Server-Side Programming Primer:
REST
Web Sockets
Server-sent Events
This presentation has been developed in the context of the Mobile Applications Development course at the Computer Science Department of the University of L’Aquila (Italy).
http://www.di.univaq.it/malavolta
Browser APIs for data exchange: types and applicationPavel Klimiankou
What browser APIs can we use for data exchange. XMLHttpRequest, fetch(), Server-Sent Events, WebSocket, WebRTC. What's the difference. Use cases for each of those.
Mobile applications Development - Lecture 17
Server-Side Programming Primer:
REST
Web Sockets
Server-sent Events
This presentation has been developed in the context of the Mobile Applications Development course at the Computer Science Department of the University of L’Aquila (Italy).
http://www.di.univaq.it/malavolta
10 Of The Best Books About TCP/IP And Networking
1.Internet Core Protocols: The Definitive Guide: Help for Network Administrators
2.Effective TCP/IP Programming: 44 Tips to Improve Your Network Programs
3.TCP/IP Explained
4.High-Speed Networks TCP/IP and ATM Design Principles
5.TCP/IP: Architecture, Protocols, and Implementation with IPv6 and IP
6.SNMP, SNMPv2, SNMPv3, and RMON 1 and 2
7.SNMP: A Guide to Network Management
8.TCP/IP Network Administration
9.Teach Yourself Tcp/Ip in 14 Days
10.UNIX Network Programming
The new standard for C++ language has been signed in 2011. This new (extended) language, called C++11, has a number of new semantics (in terms of language constructs) and a number of new standard library support. The major language extensions are discussed in this presentation. The library will be taken up in a later presentation.
Slides from a talk given at DevSecCon on 206h October 2016 http://www.devseccon.com/blog/session/automating-owasp-zap/
The OWASP Zed Attack Proxy (ZAP) is one of the world’s most popular and best maintained free security tools. In this workshop you will learn how to automate security tests using ZAP. These tests can then be included in your continuous integration / delivery pipeline. Simon will cover the range of integration options available and then walk you through automating ZAP against a test application. The ZAP UI will be used to explain the concepts and python scripting used to drive ZAP via its API – this can then also be used to drive ZAP in daemon mode.
This workshop is aimed at anyone interested in automating ZAP for security testing, including developers, functional testers (QA) and security/pentesters.
Database connectivity to sql server asp.netHemant Sankhla
This ppt will help those who are beginner in sql server, asp.net and C# and want to learn database connectivity. So i provide them the simpler code on this universe for their database enabled web or desktop application.
10 Of The Best Books About TCP/IP And Networking
1.Internet Core Protocols: The Definitive Guide: Help for Network Administrators
2.Effective TCP/IP Programming: 44 Tips to Improve Your Network Programs
3.TCP/IP Explained
4.High-Speed Networks TCP/IP and ATM Design Principles
5.TCP/IP: Architecture, Protocols, and Implementation with IPv6 and IP
6.SNMP, SNMPv2, SNMPv3, and RMON 1 and 2
7.SNMP: A Guide to Network Management
8.TCP/IP Network Administration
9.Teach Yourself Tcp/Ip in 14 Days
10.UNIX Network Programming
The new standard for C++ language has been signed in 2011. This new (extended) language, called C++11, has a number of new semantics (in terms of language constructs) and a number of new standard library support. The major language extensions are discussed in this presentation. The library will be taken up in a later presentation.
Slides from a talk given at DevSecCon on 206h October 2016 http://www.devseccon.com/blog/session/automating-owasp-zap/
The OWASP Zed Attack Proxy (ZAP) is one of the world’s most popular and best maintained free security tools. In this workshop you will learn how to automate security tests using ZAP. These tests can then be included in your continuous integration / delivery pipeline. Simon will cover the range of integration options available and then walk you through automating ZAP against a test application. The ZAP UI will be used to explain the concepts and python scripting used to drive ZAP via its API – this can then also be used to drive ZAP in daemon mode.
This workshop is aimed at anyone interested in automating ZAP for security testing, including developers, functional testers (QA) and security/pentesters.
Database connectivity to sql server asp.netHemant Sankhla
This ppt will help those who are beginner in sql server, asp.net and C# and want to learn database connectivity. So i provide them the simpler code on this universe for their database enabled web or desktop application.
Would you like to know how to build an application server from scratch? This talk would provide an insight to the thought process and the key decisions made while building WebROaR from grounds up using C & Ruby.
What enables this server to deliver high performance and also offer a rich bouquet of integrated features like Analytics, Exception Notifications etc? If gaining knowledge about design of a good software product interests you, do join us for this interactive session.
Vaadin - Rich Web Applications in Server-side Java without Plug-ins or JavaSc...Joonas Lehtinen
The Vaadin provides a desktop-like programming model on the server for creating Rich Internet Applications (RIAs) in plain Java - without the need for HTML, XML, plug-ins or JavaScript.
Session explains the key concepts of the server-side RIA development model and compares it to client-side RIA. To demonstrate the use of framework, an example application is developed during the session step-by-step. The presentation is concluded with pointers on how to start developing your own applications with Apache-licensed Vaadin-framework.
You'll learn:
* How to create a desktop like web application in Java
* Difference between page oriented, client-side RIA and server-side RIA architectures
* How Vaadin can be extended with Google Web Toolkit
More information and materials about the presentation:
http://vaadin.com/web/joonas/wiki/-/wiki/Main/Server-side%20RIA
Doi-te a passar os teus objectos para modelos relacionais? Passas mais tempo a espera de joins da base de dados do que a mostrar resultados a utilizadores? Então vem ver o que o RavenDB tem para te oferecer como solução para storage de dados.
Nesta apresentação, o Bruno vai mostrar o que é uma base de dados de documentos, razões para elas terem aparecido e principais vantagens e desvantagens em relação a RDBMS tradicionais.
Para demonstrar tudo isto irá falar dos principais conceitos de RavenDB como um documento, um índice e um query, quais os "gotchas" mais comuns e mostrar qual o fluxo de desenvolvimento com uma pequena aplicação Web.
Slides used in KCD Spain 2021 which covers challenges faced by NSM to provide a portable CNF and how a Mutating Admission Webhook helps to reduce those gaps.
Vaadin, Rich Web Apps in Server-Side Java without Plug-ins or JavaScript: Joo...jaxconf
Get introduced to the Vaadin framework by one of its core developers. Vaadin provides a desktop-like programming model on the server for creating Rich Internet Applications (RIAs) in plain Java - without the need for HTML, XML, plug-ins or JavaScript. In this session, Joonas lays out the key concepts of the server-side RIA development model and compares it to client-side RIA. To demonstrate the use of framework, an example application is developed during the session step-by-step. The presentation is concluded with pointers on how to start developing your own applications with Apache-licensed Vaadin-framework. You'll learn: * How to create a desktop like web application in Java * Difference between page oriented, client-side RIA and server-side RIA architectures * How Vaadin can be extended with Google Web Toolkit
Working with Data and Web Services in Microsoft Silverlight 2goodfriday
Learn how easy it is to utilize POX, REST, RSS, ATOM, JSON, and SOAP in your Microsoft Silverlight mashup applications. Also learn how to easily access and display data with Silverlight using LINQ and databinding.
The presentation "Development for Administrators" was presented at AdminCamp 2006 in Germany, and a revised version presented at SoftSphere in Frankfurt in October 2007. This presentation intends to show Administrators:
Introduce proper development, UAT and production environments
show some basic @Formula language agents
Show some basic LotusScript functions
Similar to "Http protocol and other stuff" by Bipin Upadhyay (20)
Attack Simulation And Threat Modeling -Olu AkindeindeBipin Upadhyay
Released by Olu Akindeinde under GNU Free Documentation license: http://old.nabble.com/Attack-Simulation-and-Threat-Modeling-book-to27540377.html#a27540377
Intro:
Attack Simulation and Threat Modeling is a book that explores the abundant resources available in advanced security data collection, classification, processing and mining. It attempts to give insight into a number of alternative methods of security and attack analytics that leverage methodologies adopted from various other disciplines in extracting valuable data to support security research work and chart a course for enterprise security decision making.
Synopsis
Threat Vectors and Attack Signatures
Attack Virtualization and Behavioural analysis
Security Event Correlation and Pattern Recognition
Exploratory Security Analytics and Threat Hypothesis
Machine Learning Algorithms
It is released under the GNU FDL v1.3 License.
A presentation on PHP Development Stack (tools for PHP Development) by my colleagues Neeraj Shah & Sharmishtha Gupta. It was presented at PHPCamp, Pune, on Sept'20th, 2008.
Blog Link: http://projectbee.org/blog/archive/how-to-implementing-shindig/
The presentation is all about getting started with implementing Shindig for your existing social portal. Presented at PHPCamp, Pune, on Sept'20th, 2008.
Can be used as a introductory presentation to web security basics. Contains intro on Attacks to Preventions Tips, organized neatly.
http://codeinmybug.wordpress.com/2007/10/12/the-web-is-broken/
GraphRAG is All You need? LLM & Knowledge GraphGuy Korland
Guy Korland, CEO and Co-founder of FalkorDB, will review two articles on the integration of language models with knowledge graphs.
1. Unifying Large Language Models and Knowledge Graphs: A Roadmap.
https://arxiv.org/abs/2306.08302
2. Microsoft Research's GraphRAG paper and a review paper on various uses of knowledge graphs:
https://www.microsoft.com/en-us/research/blog/graphrag-unlocking-llm-discovery-on-narrative-private-data/
State of ICS and IoT Cyber Threat Landscape Report 2024 previewPrayukth K V
The IoT and OT threat landscape report has been prepared by the Threat Research Team at Sectrio using data from Sectrio, cyber threat intelligence farming facilities spread across over 85 cities around the world. In addition, Sectrio also runs AI-based advanced threat and payload engagement facilities that serve as sinks to attract and engage sophisticated threat actors, and newer malware including new variants and latent threats that are at an earlier stage of development.
The latest edition of the OT/ICS and IoT security Threat Landscape Report 2024 also covers:
State of global ICS asset and network exposure
Sectoral targets and attacks as well as the cost of ransom
Global APT activity, AI usage, actor and tactic profiles, and implications
Rise in volumes of AI-powered cyberattacks
Major cyber events in 2024
Malware and malicious payload trends
Cyberattack types and targets
Vulnerability exploit attempts on CVEs
Attacks on counties – USA
Expansion of bot farms – how, where, and why
In-depth analysis of the cyber threat landscape across North America, South America, Europe, APAC, and the Middle East
Why are attacks on smart factories rising?
Cyber risk predictions
Axis of attacks – Europe
Systemic attacks in the Middle East
Download the full report from here:
https://sectrio.com/resources/ot-threat-landscape-reports/sectrio-releases-ot-ics-and-iot-security-threat-landscape-report-2024/
Kubernetes & AI - Beauty and the Beast !?! @KCD Istanbul 2024Tobias Schneck
As AI technology is pushing into IT I was wondering myself, as an “infrastructure container kubernetes guy”, how get this fancy AI technology get managed from an infrastructure operational view? Is it possible to apply our lovely cloud native principals as well? What benefit’s both technologies could bring to each other?
Let me take this questions and provide you a short journey through existing deployment models and use cases for AI software. On practical examples, we discuss what cloud/on-premise strategy we may need for applying it to our own infrastructure to get it to work from an enterprise perspective. I want to give an overview about infrastructure requirements and technologies, what could be beneficial or limiting your AI use cases in an enterprise environment. An interactive Demo will give you some insides, what approaches I got already working for real.
Smart TV Buyer Insights Survey 2024 by 91mobiles.pdf91mobiles
91mobiles recently conducted a Smart TV Buyer Insights Survey in which we asked over 3,000 respondents about the TV they own, aspects they look at on a new TV, and their TV buying preferences.
Elevating Tactical DDD Patterns Through Object CalisthenicsDorra BARTAGUIZ
After immersing yourself in the blue book and its red counterpart, attending DDD-focused conferences, and applying tactical patterns, you're left with a crucial question: How do I ensure my design is effective? Tactical patterns within Domain-Driven Design (DDD) serve as guiding principles for creating clear and manageable domain models. However, achieving success with these patterns requires additional guidance. Interestingly, we've observed that a set of constraints initially designed for training purposes remarkably aligns with effective pattern implementation, offering a more ‘mechanical’ approach. Let's explore together how Object Calisthenics can elevate the design of your tactical DDD patterns, offering concrete help for those venturing into DDD for the first time!
UiPath Test Automation using UiPath Test Suite series, part 3DianaGray10
Welcome to UiPath Test Automation using UiPath Test Suite series part 3. In this session, we will cover desktop automation along with UI automation.
Topics covered:
UI automation Introduction,
UI automation Sample
Desktop automation flow
Pradeep Chinnala, Senior Consultant Automation Developer @WonderBotz and UiPath MVP
Deepak Rai, Automation Practice Lead, Boundaryless Group and UiPath MVP
GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using Deplo...James Anderson
Effective Application Security in Software Delivery lifecycle using Deployment Firewall and DBOM
The modern software delivery process (or the CI/CD process) includes many tools, distributed teams, open-source code, and cloud platforms. Constant focus on speed to release software to market, along with the traditional slow and manual security checks has caused gaps in continuous security as an important piece in the software supply chain. Today organizations feel more susceptible to external and internal cyber threats due to the vast attack surface in their applications supply chain and the lack of end-to-end governance and risk management.
The software team must secure its software delivery process to avoid vulnerability and security breaches. This needs to be achieved with existing tool chains and without extensive rework of the delivery processes. This talk will present strategies and techniques for providing visibility into the true risk of the existing vulnerabilities, preventing the introduction of security issues in the software, resolving vulnerabilities in production environments quickly, and capturing the deployment bill of materials (DBOM).
Speakers:
Bob Boule
Robert Boule is a technology enthusiast with PASSION for technology and making things work along with a knack for helping others understand how things work. He comes with around 20 years of solution engineering experience in application security, software continuous delivery, and SaaS platforms. He is known for his dynamic presentations in CI/CD and application security integrated in software delivery lifecycle.
Gopinath Rebala
Gopinath Rebala is the CTO of OpsMx, where he has overall responsibility for the machine learning and data processing architectures for Secure Software Delivery. Gopi also has a strong connection with our customers, leading design and architecture for strategic implementations. Gopi is a frequent speaker and well-known leader in continuous delivery and integrating security into software delivery.
Connector Corner: Automate dynamic content and events by pushing a buttonDianaGray10
Here is something new! In our next Connector Corner webinar, we will demonstrate how you can use a single workflow to:
Create a campaign using Mailchimp with merge tags/fields
Send an interactive Slack channel message (using buttons)
Have the message received by managers and peers along with a test email for review
But there’s more:
In a second workflow supporting the same use case, you’ll see:
Your campaign sent to target colleagues for approval
If the “Approve” button is clicked, a Jira/Zendesk ticket is created for the marketing design team
But—if the “Reject” button is pushed, colleagues will be alerted via Slack message
Join us to learn more about this new, human-in-the-loop capability, brought to you by Integration Service connectors.
And...
Speakers:
Akshay Agnihotri, Product Manager
Charlie Greenberg, Host
Dev Dives: Train smarter, not harder – active learning and UiPath LLMs for do...UiPathCommunity
💥 Speed, accuracy, and scaling – discover the superpowers of GenAI in action with UiPath Document Understanding and Communications Mining™:
See how to accelerate model training and optimize model performance with active learning
Learn about the latest enhancements to out-of-the-box document processing – with little to no training required
Get an exclusive demo of the new family of UiPath LLMs – GenAI models specialized for processing different types of documents and messages
This is a hands-on session specifically designed for automation developers and AI enthusiasts seeking to enhance their knowledge in leveraging the latest intelligent document processing capabilities offered by UiPath.
Speakers:
👨🏫 Andras Palfi, Senior Product Manager, UiPath
👩🏫 Lenka Dulovicova, Product Program Manager, UiPath
LF Energy Webinar: Electrical Grid Modelling and Simulation Through PowSyBl -...DanBrown980551
Do you want to learn how to model and simulate an electrical network from scratch in under an hour?
Then welcome to this PowSyBl workshop, hosted by Rte, the French Transmission System Operator (TSO)!
During the webinar, you will discover the PowSyBl ecosystem as well as handle and study an electrical network through an interactive Python notebook.
PowSyBl is an open source project hosted by LF Energy, which offers a comprehensive set of features for electrical grid modelling and simulation. Among other advanced features, PowSyBl provides:
- A fully editable and extendable library for grid component modelling;
- Visualization tools to display your network;
- Grid simulation tools, such as power flows, security analyses (with or without remedial actions) and sensitivity analyses;
The framework is mostly written in Java, with a Python binding so that Python developers can access PowSyBl functionalities as well.
What you will learn during the webinar:
- For beginners: discover PowSyBl's functionalities through a quick general presentation and the notebook, without needing any expert coding skills;
- For advanced developers: master the skills to efficiently apply PowSyBl functionalities to your real-world scenarios.
12. Agenda
Intro: What & Why???
OSI model: Back to the basics
10000 feet view: How the web works
RFC 2616: Anatomy
RFC 2965: Handling Statelessness
13. Agenda
Intro: What & Why???
OSI model: Back to the basics
10000 feet view: How the web works
RFC 2616: Anatomy
RFC 2965: Handling Statelessness
14. Bit of History
Mar’89 – T.B. Lee presents “Information Management:
A Proposal”
Aug’91 – Announces WWW
Mar’93 – Mosaic announced
Mar’94 – Netscape found
Oct’94 – W3C found by T.B. Lee
16. HTTP: What is it?
Part of the Application Layer of TCP/IP protocol suite
17. HTTP: What is it?
Part of the Application Layer of TCP/IP protocol suite
A set of grammatical rules for a client and server to
communicate
http://www.flickr.com/photos/joshfassbind/4584323789/
18. HTTP: What is it?
Part of the Application Layer of TCP/IP protocol suite
A set of grammatical rules for a client and server to
communicate
HTTP is what powers the WWW
24. Agenda
Intro: What & Why???
OSI model: Back to the basics
10000 feet view: How the web works
RFC 2616: Anatomy
RFC 2985: Handling Statelessness
http://www.flickr.com/photos/stephenpoff/2312981944/
25. OSI & TCP/IP protocol suite
OSI is a reference model
http://blog.uad.ac.id/imam_riadi/files/2009/01/osi-layer.jpg
26. OSI & TCP/IP protocol suite…
TCP/IP protocol suite is implementation of OSI
http://www.hill2dot0.com/wiki/index.php?title=Image:G0209_TCPIP_vs_OSI.jpg
28. Agenda
Intro: What & Why???
OSI model: Back to the basics
10000 feet view: How the web works
RFC 2616: Anatomy
RFC 2965: Handling Statelessness
29. The Communication
My favorite interview question:
http://www.flickr.com/photos/terryhart/2890904949/
30. The Communication
My favorite interview question:
What all happens between the time when:
and the page is
we click on a completely
hyperlink rendered in a
browser
31. Web DB
Brower Proxy Internetz LB
Server Server
32. Client Server (null.co.in)
Web DB
Brower Proxy Internetz LB
Server Server
33. Client Server (null.co.in)
Web DB
Brower Proxy Internetz LB
Server Server
null.co.in
Browser cache/ hosts
file/ DNS server
34. Client Server (null.co.in)
Web DB
Brower Proxy Internetz LB
Server Server
null.co.in
74.53.228.212
Browser cache/ hosts
file/ DNS server
35. Client Server (null.co.in)
Web DB
Brower Proxy Internetz LB
Server Server
SYN
TCP Connection: There, bro?
36. Client Server (null.co.in)
Web DB
Brower Proxy Internetz LB
Server Server
SYN
SYN-ACK
TCP Connection: Yo!
37. Client Server (null.co.in)
Web DB
Brower Proxy Internetz LB
Server Server
SYN
SYN-ACK
ACK
TCP Connection: Cool!
38. Client Server (null.co.in)
Web DB
Brower Proxy Internetz LB
Server Server
GET /
HTTP: Got this file?
39. Client Server (null.co.in)
Web DB
Brower Proxy Internetz LB
Server Server
GET /
200 OK
index.html
HTTP: Yup! Here ‘tis.
40. Client Server (null.co.in)
Web DB
Brower Proxy Internetz LB
Server Server
GET /
200 OK
index.html
GET /js.js
GET /pic.jpg
HTTP: Can I have these as well?
41. Client Server (null.co.in)
Web DB
Brower Proxy Internetz LB
Server Server
GET /
200 OK
index.html
GET /js.js
GET /pic.jpg
200 OK
more content…
HTTP: Sure!
42. Client Server (null.co.in)
Web DB
Brower Proxy Internetz LB
Server Server
FIN
TCP Connection: Arigato, am done.
43. Client Server (null.co.in)
Web DB
Brower Proxy Internetz LB
Server Server
FIN
FIN-ACK
TCP Connection: Sayonara!
45. The Communication
Web 2.0 has shrunk the client and server distinction
Conventionally, client sends an HTTP request
Server responds with an HTTP response
46. The Communication: HTTP Request
Request Line
Request Method
Requested Resource
HTTP Version used
Headers
General Headers
Request Headers
Entity Headers
Content (Optional)
47. The Communication: HTTP Response
Status Line
HTTP version(s) understood by server
Status code (3 digit numerical value)
Status description
Headers
General Headers
Response Headers
Entity Headers
Content (Optional)
48. Agenda
Intro: What & Why???
OSI model: Back to the basics
10000 feet view: How the web works
RFC 2616: Anatomy
RFC 2965: Handling Statelessness
http://www.saynotocrack.com/wp-content/uploads/2007/06/flinstones-anatomy.jpg
49. Anatomy
HTTP Request and Response are comprised of various
components:
Request Methods
Response Status Codes
Request Headers
Response Headers
General Headers
Entity Headers
Content (MIME Media Types)
50. Anatomy: Request Methods
Humans can convey emotions in several ways
Why should HTTP clients lag!!!
HTTP methods describe the type of communication
GET POST HEAD OPTIONS
TRACE PUT DELETE CONNECT
51. Anatomy: Response Status Codes
Indicate the server’s mood corresponding to a request
Combination of a numerical code, and a short
description
Cab be categorized in 5 categories:
1xx -- Informational
2xx -- Successful
3xx -- Redirection
4xx -- Client Error
5xx -- Server Error
52. Anatomy: Request Headers
Specific to an HTTP Request
Carry information about the client, and the type of
request
Facilitates better understanding between client and
server
Host Accept-Language If-Modified-Since Referer
User-Agent Authorization If-None-Match Expect
Accept Proxy- If-Range From
Authorization
Accept-Charset Max-Forwards If-Unmodified- TE
Since
Accept-Encoding If-Match Range
53. Anatomy: Response Headers
Specific to an HTTP Response
Carry information about the server, and the type of
response
Accept-Ranges ETag Retry-After WWW-Authenticate
Age Location Server Proxy-Authenticate
Vary
54. Anatomy: General Headers
Carry information about the HTTP transaction
Can be a part of request, as well as response
Cache-Control Keep-Alive Pragma Via
Connection Upgrade Trailer Warning
Transfer-Encoding Date
55. Anatomy: Entity Headers
Carry information about the content
Mainly a part of HTTP response
Allow Content-Language Content-Location Content-Range
Content-Encoding Content-Length Content-MD5 Content-Type
Expires Last-Modified
56. Anatomy: Content
IANA maintains a list of valid content types
It is specified by the Content-Type Entity header
Categorized in 9 MIME Media types:
application audio example image
message model multipart text
video
57. Agenda
Intro: What & Why???
OSI model: Back to the basics
10000 feet view: How the web works
RFC 2616: Anatomy
RFC 2965: Handling Statelessness