This site is archived.

A matter of safety: Security Practices in Drupal

a matter of safety
Code & Development

A matter of safety: Security Practices in Drupal

45 minutes (+15 minutes Q&A)

Room:

tags

In this session you will learn about common security website holes, how hackers use them and what you can do as site developer/maintainer to prevent security breeches. Following topics will be discussed:

  • Explanation of top 10 security holes categories by OWASP
  • Types of attack: it is not just your Drupal site that can be compromised. You will learn about the weak spots in your providers’ web server and beyond
  • How to use Drupal in a secure way
  • Using permission system properly to secure your applications
  • User input output in Drupal and how to prevent hacking through I/O operations
  • Drupal security API
  • Contributed security modules and automatic security testing tools
  • Couple of real world examples: how poorly coded/configured site opens backdoors for hackers and how to enter through those doors

Perhaps you will not become a security expert by the end of this session ;) but you will learn about the sources of danger and about the ways to protect yourself.

Resources

good, +1

3. July 2010 - 9:59

good, +1

Perhaps you can do a joint

10. July 2010 - 18:44

Perhaps you can do a joint presentation with the guys from http://cph2010.drupal.org/sessions/drupal-security-configuration-and-pro... ?