Web App Vulnerabilities - DevSecOps Course for Beginners

Поделиться
HTML-код
  • Опубликовано: 30 май 2024
  • In this DevSecOps course, you will learn how to take advantage of common web vulnerabilities, how to fix those vulnerabilities, and how to use DevSecOps tools to make sure your applications (and containers) are secure. You will also learn all about DevSecOps.
    💻 Get the goof example app shown in this course: github.com/snyk/goof
    🎉 Thanks to Snyk for providing a grant that made this course possible.
    🔗 Sign up for Snyk: snyk.io/try-devsecops
    🔗 Learn more about DevSecOps: learn.snyk.io/
    ✏️ Beau Carnes developed this course.
    ✏️ Eric Smalling teaches the last section of the course about securing containers. Eric is a Senior Developer Advocate at Snyk.io and has over 30 years of enterprise application development and consulting experience.
    🔗 Eric is @ericsmalling on most social platforms (Twitter, LinkedIn, GitHub)
    ⭐️ Course Contents ⭐️
    ⌨️ (00:00:00) Introduction
    ⌨️ (00:00:29) What is DevSecOps?
    ⌨️ (00:01:12) Vulnerabilities
    ⌨️ (00:08:11) DevOps vs DevSecOps
    ⌨️ (00:14:02) Software Project Iceberg
    ⌨️ (00:15:25) Importance of DevSecOps
    ⌨️ (00:17:45) Exploiting Common Web App Vulnerabilities
    ⌨️ (00:37:53) Finding and Fixing Vulnerabilities with Snyk Code
    ⌨️ (00:49:01) Exploring Vulnerabilities Using the Snyk Web Interface
    ⌨️ (00:52:22) Securing Containers (featuring Eric Smalling)
    ⌨️ (01:28:31) Conclusion
    🎉 Thanks to our Champion and Sponsor supporters:
    👾 Raymond Odero
    👾 Agustín Kussrow
    👾 aldo ferretti
    👾 Otis Morgan
    👾 DeezMaster
    --
    Learn to code for free and get a developer job: www.freecodecamp.org
    Read hundreds of articles on programming: freecodecamp.org/news

Комментарии • 72

  • @koolitsch
    @koolitsch 6 дней назад

    because of this channel i started understanding to code and IT in general i started watching and learning by myself and this channel in 2020 (october) almost 4 years and i feel confortable in many areas! if your at your beginning an reading this! keep going its a never ending journey of wisdom! :) thanks baeu u changed my life with youtube tutorials!:)

  • @user-hi4eh6lm8c
    @user-hi4eh6lm8c 5 месяцев назад +3

    That youtube channel by all means, is a gift to the programming world and all it’s end users.

  • @SSNUTHIN
    @SSNUTHIN 2 года назад +20

    I am finding it totally hilarious this went live so close to the Oracle vulnerability.

  • @fancypants2182
    @fancypants2182 2 года назад +7

    I understand less then 10% but it's so cool watching these people talk

  • @maddutchess5312
    @maddutchess5312 2 года назад +4

    You rock, Beau. Thanks again. Keep up the great work.

  • @BobBob-qm2bm
    @BobBob-qm2bm Год назад +10

    Beau this is good content...please create more appsec | webappsec | devsecops training from you. Thanks for sharing the knowledge

  • @fernandoflores4656
    @fernandoflores4656 2 года назад +4

    After flirting with the idea of entering this space, I've always felt the need to learn the techniques used to build better solutions. In fact, this is what crippled me when ever given the idea of pursuing development. I know keep it simple and readable, but because of how I think and function I just couldn't let this go to chance. My code needs to be at least somewhat secure or its just going to require rewriting. Can't wait to see what he does next. My guy, I'd love to ask for a path. I generally ask for direction only, but in this case with this much material, I could really use a plan.
    Recently took an interview with an unnamed company that I am ecstatic about and also ready to jump into a DevOps role where I would like to bring Security to the forefront.

  • @lisali6205
    @lisali6205 2 года назад +21

    This man seems so smart. I have followed him to finish a Mern stack project, but he keeps posting new tutorial video. How could he learn so fast ?

    • @patrykp8460
      @patrykp8460 11 месяцев назад +1

      The man probably got army of people helping him out, but still he knows tons

  • @chmodheshan5291
    @chmodheshan5291 2 года назад +11

    Uncle,you and your team is awesome thanks man very good..😙😍

  • @hope.1503
    @hope.1503 2 года назад +1

    ty 4 making this! wish for a more advanced follow-up to this

  • @laljondi
    @laljondi 2 года назад

    Hi, thanks for sharing the knowledge and for this course!

  • @subhasispattanaik1094
    @subhasispattanaik1094 2 года назад +4

    🔥🔥.. that's what I was looking for..

  • @brawlbox145
    @brawlbox145 2 года назад +1

    I just started to learning...Thnx a Lot for sharing knowledge...

  • @vishaloza6981
    @vishaloza6981 2 года назад +3

    Thanks for the early Christmas present!

  • @b391i
    @b391i 2 года назад +4

    Awesome as usual 👊😎

  • @theatypicaldeveloper
    @theatypicaldeveloper 2 года назад +11

    I think that web app's security is often ignored when developing an app or introducing new features. I really enjoyed 'exploying vulnerabilities' part of the vide. Thanks for sharing your knowledge.

  • @alimianabadi86
    @alimianabadi86 Год назад

    Thanks for sharing the knowledge and please create more video's or introduce other videos for this course

  • @efosaobasuyi5243
    @efosaobasuyi5243 Месяц назад

    This is really, good stuff guys.

  • @gmolashvili
    @gmolashvili 2 года назад

    Very cool. Please create more videos on security

  • @0xtz_
    @0xtz_ 2 года назад +16

    We need more 🔥

  • @deepakr_
    @deepakr_ 2 года назад +11

    Guys, I m QA Automation engineer. I wanted to learn and Shift to DevOps. Could you Please do a video on this and help us ? Too many courses on RUclips

    • @freecodecamp
      @freecodecamp  2 года назад +7

      Here is a good DevOps video: ruclips.net/video/j5Zsa_eOXeY/видео.html

  • @iasoto
    @iasoto 2 года назад +1

    Excellent!

  • @tosinfaleyimu8405
    @tosinfaleyimu8405 2 года назад

    You can definitely read my mind!

  • @mohamadbathulah5783
    @mohamadbathulah5783 Год назад

    Thanks, really helpful

  • @thepriyank121
    @thepriyank121 9 месяцев назад

    nice guys looking fwd to enroll full time dev sec ops

  • @rstark
    @rstark 2 года назад +2

    Thanks!

  • @Eltopshottah
    @Eltopshottah 2 года назад +3

    Hoodie up that boy ain’t playing

  • @htcsaj7876
    @htcsaj7876 2 года назад

    Is there any react js landing page for business website with basic CSS.

  • @sambhavjain6929
    @sambhavjain6929 2 месяца назад

    42:53 synk code vulnerability scanner it has red orange yello grey alert colours ,, devops and sdlc pipeline,images runtime and kubernetes defence in depth ,

  • @xeatcrowsx
    @xeatcrowsx 2 года назад

    I'm just starting a MERN full stack but man I'm feeling like code camp is throwing me warp speed into new learning modules.

  • @tranquillityEnthusiast
    @tranquillityEnthusiast 2 года назад +1

    Please make video on mean stack for 10 to 15 hours.. with multiple big projexts

  • @cciedclab3754
    @cciedclab3754 2 года назад

    Excellent video

  • @Kim-xz7oz
    @Kim-xz7oz 2 года назад

    Where did you get your background? It is nice though

  • @WeconTechnology
    @WeconTechnology 2 года назад

    thanks for you video, nice.

  • @amruthaj4262
    @amruthaj4262 3 месяца назад

    What are the prerequisites to learn DevSecOps? Can anyone let me know this?

  • @brandonhunter7164
    @brandonhunter7164 Год назад

    I'm so confused about what terminal is being used and how to get to the Node.js directory. Can someone point me in the right direction or explain it in leymans terms. Please and Thank you.

  • @saplay3372
    @saplay3372 2 года назад +1

    All the best

  • @ghostwriter3274
    @ghostwriter3274 2 года назад

    nice backround!

  • @centralbiz5974
    @centralbiz5974 2 года назад +5

    haha Beau using a hood is very convenient for this subject ....

  • @BleakDeath
    @BleakDeath Год назад

    I love this

  • @CHITUS
    @CHITUS 2 года назад

    We need more

  • @exploretheworld2forgetyourself
    @exploretheworld2forgetyourself 2 года назад

    Please guide me how to get real time experience on devops without working in a company to get a job

  • @kapilsharma4722
    @kapilsharma4722 2 года назад +1

    Latest case Log4j vulnerability

  • @justinbeam4233
    @justinbeam4233 2 года назад +1

    I wish every single security related video on youtube didnt involves a hoodie with the hood up

  • @fahadbawazir1771
    @fahadbawazir1771 2 года назад +3

    Good but we need full VIDEOS

  • @disrael2101
    @disrael2101 9 месяцев назад

    i'm facing an error running the docker-compose up --build: no matching manifest for linux/arm64/v in the manifest list entries
    also:
    failed to solve: process "/bin/sh -c npm update" did not complete successfully: exit code: 1

    • @user-bq9mz1oj1u
      @user-bq9mz1oj1u 9 месяцев назад

      i am having busboy in not a constructor error

  • @bmejia220
    @bmejia220 2 года назад

    Are mobile apps open to these same vulnerabilities?

  • @priyavathana6606
    @priyavathana6606 2 года назад +4

    21st view and 1st comment.

  • @sajeeb7431
    @sajeeb7431 2 года назад +2

    Can we have Android dev videos

  • @roguegenesis7020
    @roguegenesis7020 2 года назад

    Beau looking like a hacker today😂

  • @vamsi8569
    @vamsi8569 2 года назад +3

    Watching 0:15

  • @hamza77v
    @hamza77v Год назад +1

    ❣️🔥

  • @YashTrivedi21
    @YashTrivedi21 2 года назад +16

    I think they thought of this after log4j disaster. LoL

  • @cailizhang1193
    @cailizhang1193 2 года назад +4

    Log4j

  • @ryanisthewind
    @ryanisthewind 6 месяцев назад

    he got a hoodie, I know I can trust him

  • @sumitsony
    @sumitsony 2 года назад

  • @shreyasrajanna7361
    @shreyasrajanna7361 2 года назад

    Future job title devsecops-ceo-manager-investor-janitor-gardner 😂😂

  • @_MrCode
    @_MrCode 2 года назад +1

    Hello
    i am involved in a problem can any one help me
    i want to make a browser i have learnt c++ and C# as a beigner programmer
    anyone can guide me how and from where i start to build browser
    which things i need to learn. which things are required to make browser

    • @freecodecamp
      @freecodecamp  2 года назад +2

      Just for a learning experience or as a product for others to learn? If the second option, you should base it off of Chomium. Most browsers are based on Chomium.

    • @rosgori
      @rosgori 2 года назад +1

      Also you can look at how Firefox is built

    • @_MrCode
      @_MrCode 2 года назад

      @@rosgori THANK YOU SO MUCH

  • @yusufakbulut3196
    @yusufakbulut3196 5 месяцев назад +1

    for those who gets ERROR: "[BUG]: Connect 500 TypeError: Busboy is not a constructor" the fix is the folowing:
    Steps to solve in Dockerfile
    Edit the dependencies object in package.json file.
    Replace the following two dependencies to more up to date versions
    Before
    "express": "4.12.4",
    "express-fileupload": "0.0.5",
    After
    "express": "4.17.1",
    "express-fileupload": "1.4.0",

  • @adnanpramudio6109
    @adnanpramudio6109 2 года назад +1

    You look like hackerman haha

  • @lakshmiprabhakarkoppolu9100
    @lakshmiprabhakarkoppolu9100 Год назад

    The most confusing topic for Devops Engineers is DevSecOps, now AI-ML-OPS.hmmm.. I dont know what will be the buzzword for 2024

  • @Dan-codes
    @Dan-codes 2 года назад +1

    Hacking, step 1: buy a hoodie and have monitors scan the globe.

  • @Joseph-gs3iq
    @Joseph-gs3iq 20 дней назад

    very good vul burp nessus zap nikto testing and hedgus waf i choose both of them

  • @kevindii7480
    @kevindii7480 6 месяцев назад

    Thanks!