EPISODE · Sep 11, 2018 · 28 MIN
Niels Tanis -- A Slice of the Razor with ASP.Net Core
from The Application Security Podcast · host Chris Romeo and Robert Hurlbut
Framework defaults can prevent common vulnerabilities, but developers still need to understand when their code bypasses those protections. Niels Tanis joins the podcast at AppSecEU to unpack ASP.NET Core and Razor Pages from a security perspective. He explains the framework’s structure, dependency and package concerns, and the protections around request forgery and output encoding. The conversation explores why rendering raw HTML deserves scrutiny, how validation and model state work, and how overposting can expose fields that never appear in the interface. Niels also discusses tooling and ways to begin learning the platform. This archive episode gives .NET developers a practical way to reason about what the framework does for them and which responsibilities remain in their application code.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Niels Tanis:→ Niels Tanis on LinkedInMentioned in this episode:→ ASP.NET Core Razor Pages documentation→ ASP.NET Core documentation→ NuGet→ Scott Hanselman on overposting and mass assignmentFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 ASP.NET Core and Razor security with Niels Tanis01:25 Niels’s security origin story03:44 The security implications of a changing .NET platform05:57 Understanding ASP.NET Core and MVC07:54 Framework and dependency challenges12:41 Razor Pages and security defaults14:16 Baseline protections and output encoding16:16 Why raw HTML deserves extra review17:26 Explicitly overriding secure defaults19:52 Security tooling through NuGet20:24 Input validation and model state21:55 Overposting and mass assignment26:23 Where new .NET developers can learn more
Embed this episode
What this episode covers
Framework defaults can prevent common vulnerabilities, but developers still need to understand when their code bypasses those protections. Niels Tanis joins the podcast at AppSecEU to unpack ASP.NET Core and Razor Pages from a security perspective. He explains the framework’s structure, dependency and package concerns, and the protections around request forgery and output encoding. The conversation explores why rendering raw HTML deserves scrutiny, how validation and model state work, and how...
Ready to play
Niels Tanis -- A Slice of the Razor with ASP.Net Core
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.