Niels Tanis -- A Slice of the Razor with ASP.Net Core episode artwork

EPISODE · Sep 11, 2018 · 28 MIN

Niels Tanis -- A Slice of the Razor with ASP.Net Core

from The Application Security Podcast · host Chris Romeo and Robert Hurlbut

Framework defaults can prevent common vulnerabilities, but developers still need to understand when their code bypasses those protections. Niels Tanis joins the podcast at AppSecEU to unpack ASP.NET Core and Razor Pages from a security perspective. He explains the framework’s structure, dependency and package concerns, and the protections around request forgery and output encoding. The conversation explores why rendering raw HTML deserves scrutiny, how validation and model state work, and how overposting can expose fields that never appear in the interface. Niels also discusses tooling and ways to begin learning the platform. This archive episode gives .NET developers a practical way to reason about what the framework does for them and which responsibilities remain in their application code.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Niels Tanis:→ Niels Tanis on LinkedInMentioned in this episode:→ ASP.NET Core Razor Pages documentation→ ASP.NET Core documentation→ NuGet→ Scott Hanselman on overposting and mass assignmentFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 ASP.NET Core and Razor security with Niels Tanis01:25 Niels’s security origin story03:44 The security implications of a changing .NET platform05:57 Understanding ASP.NET Core and MVC07:54 Framework and dependency challenges12:41 Razor Pages and security defaults14:16 Baseline protections and output encoding16:16 Why raw HTML deserves extra review17:26 Explicitly overriding secure defaults19:52 Security tooling through NuGet20:24 Input validation and model state21:55 Overposting and mass assignment26:23 Where new .NET developers can learn more

Episode metadata supplied by the publisher feed · Published Sep 11, 2018

Embed this episode

Framework defaults can prevent common vulnerabilities, but developers still need to understand when their code bypasses those protections. Niels Tanis joins the podcast at AppSecEU to unpack ASP.NET Core and Razor Pages from a security perspective. He explains the framework’s structure, dependency and package concerns, and the protections around request forgery and output encoding. The conversation explores why rendering raw HTML deserves scrutiny, how validation and model state work, and how...

Distinct summary based on available episode metadata or transcript content.

Ready to play

Niels Tanis -- A Slice of the Razor with ASP.Net Core

0:00 28:41

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 28 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on September 11, 2018.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!