Stanford CS253: Web Security
cs253.stanford.edu
cs253.stanford.edu
The CORS content is solid. But the vulnerabilities themselves are dated. As a threshold concern, a 2020 web security class needs to be teaching about SSRF, the most important current web bug class. OAuth flows would be another thing I'd hope to see covered.
There's always going to be new stuff that can't be covered; I understand how these curricula work†, and don't expect HTTP Request Smuggling or DNS fingerprinting on the final. But system("cat ${input}")?
† The network security course taught at major CS research universities was written at one place like 10 years ago and shared and handed down from semester to semester; I assume something similar happens here.
PS
3 hours is a bananas amount of time to get for this exam. We're speedrunning it on Slack and the median is closer to 15 minutes (albeit without writing careful answers). If this were a commuter school with students who don't come in knowing how to code, sure; but this is Stanford CS!
> † The network security course taught at major CS research universities was written at one place like 10 years ago and shared and handed down from semester to semester; I assume something similar happens here.
This couldn't ring more true, in my experience. Whats worse is that each year the material is lightly modified so that you're also dealing with 10 years of revisions creating an incoherent mess.
Covers just about everything a software engineer (or web developer) needs to learn in order to get into security.
there's slides, video, and linked readings for all the sessions in this class, though.
>When accepting untrusted input from the user, we should escape it before it is added to thedatabase so that we can later use it without worrying about escaping.
I tend to believe that despite very popular saying `escape everything!!!` it isn't so practical
Let's say I have ASP.NET Core WebAPI which is using EF Core + Vuejs on frontend
I'm accepting user input which is being binded to model (class) without escaping and saving it straight to db (ofcs after basic validation like strings length and business logic)
I'm using parametrized queries, so I don't have to worry about about SQLi, then I'm returning that data as json and the client (frontend, vuejs) escapes it and renders as text.
If I escaped that data before e.g `Germany / Berlin / 15B` after escape it'd be `Germany \/ Berlin \/ 15B`
then it'd less practical to use thing kind of data because whenever you'd want to use it, then you'd have to take into account that there may be some "weird" characters.
So how it is? I tend to believe that sql parameters and escaping on client side should be done instead of escaping at the beginning
Also I tend to believe that SQLi should be non-existent problem nowadays(and before tbh) because it's always possible to compare ASTs. SQLi will always? modify AST, yea?
In a way, course pages aren't a great basis for an HN thread. They're a list of more specific topics, and lists don't work so well on HN, which itself is already a list. I think you can see this already in the comments here as well as in the previous thread: they tend to be generic (e.g. security in general) rather than diving into specifics where the real juice would be.
https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que...
https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que...