Security in ASP.NET Core
2h 37mIntermediate2024-10-10
Authors

Christian Wenz
Web Pioneer, Technology Specialist, Entrepreneur
Course details
As many as nine out of ten web applications have security vulnerabilities. Luckily, ASP.NET Core developers have a multitude of security tools at their disposal, built right into the framework. Once activated, these features can prevent and mitigate the most common and dangerous types of attacks. Learn how to build on the basic security principles you may already know and incorporate practical solutions for defending your ASP.NET Core web applications. Instructor Christian Wenz explores the risks ASP.NET apps face, including the OWASP Top Ten vulnerabilities, cross-site scripting, and SQL injection, and countermeasures to combat them. Find out how to authenticate users, store data securely, and harden your site's configuration with this practical, hands-on course that will transform your ASP.NET Core apps into impenetrable architectures.
Learning objectives
Summarize the major risks for web applications today.
Defend your ASP.NET Core based web application against common attacks.
Adapt browser security features from ASP.NET Core.
Learning objectives
Summarize the major risks for web applications today.
Defend your ASP.NET Core based web application against common attacks.
Adapt browser security features from ASP.NET Core.
Skills covered
ASP.NETBack-End Web DevelopmentFull-Stack Web DevelopmentIncident ResponseFront-End Web DevelopmentEssential TrainingCybersecurityWeb DevelopmentMicrosoft
Concepts
0. Introduction
- 01 - Why ASP.Net Core
- 02 - The importance of security in ASP.NET Core
- 03 - What you should know
- 04 - Sample ASP.NET Core application introduction
- 05 - Sample ASP.NET Core application tour
1. Mitigating Common Attacks
- 06 - OWASP Top Ten
- 07 - Cross-site scripting (XSS) - The attack
- 08 - Cross-site scripting (XSS) - The defense
- 09 - Cross-site scripting (XSS) in JavaScript
- 10 - Cross-site scripting (XSS) in single-page applications
- 11 - Same-origin policy and CORS
- 12 - Enabling CORS in ASP.NET Core web API
- 13 - SQL injection with ADO.NET
- 14 - SQL injection with Entity Framework Core
- 15 - Fixing SQL injection
- 16 - Cross-Site Request Forgery (CSRF) - The attack
- 17 - Cross-Site Request Forgery (CSRF) - The defense
2. Secure Data Storage
- 18 - Encryption fundamentals
- 19 - Secure data storage options
- 20 - More storage options
- 21 - Password hashing options
- 22 - Adding password hashing to the app
3. Authentication and Authorization
- 23 - Setting up ASP.NET Core Identity
- 24 - Scaffolding ASP.NET Core Identity files
- 25 - Adding authorization
- 26 - Securing APIs
- 27 - Further security options
4. Secure Configuration
- 28 - Understanding Cookie Options
- 29 - Securing sessions
- 30 - Securing cookie attributes in the app
- 31 - Enforcing HTTPS
- 32 - Error handling
- 33 - Hiding server information
- 34 - Security HTTP headers
Conclusion
- 35 - Next steps