Laravel Security: Top 7 Mistakes Developers Make

Laravel Security: Top 7 Mistakes Developers Make

Laravel Daily

2 года назад

81,966 Просмотров

Ссылки и html тэги не поддерживаются


Комментарии:

Programmer Yk
Programmer Yk - 28.09.2023 21:09

please make one about file upload exploit

Ответить
Sahir Khan
Sahir Khan - 26.07.2023 09:12

love from pakistan

Ответить
Edgars Vanags
Edgars Vanags - 15.05.2023 07:36

S

Ответить
M A A Z K H A N
M A A Z K H A N - 11.03.2023 10:55

You are just awesome <3

Ответить
Sherzod Qudratov
Sherzod Qudratov - 27.01.2023 22:44

First of all, big thanks, what about xml attack? And sql injections? Have any vulnerability for sql injections in laravel? If yes, how can it be safer?

Ответить
Ayenew Yihune
Ayenew Yihune - 22.12.2022 12:14

Very informative

Ответить
Timoteo Bega
Timoteo Bega - 12.12.2022 22:19

👋👋

Ответить
0x0456
0x0456 - 12.11.2022 02:28

Great video as always, would love to see more of these!

Ответить
Rejowan Ahmed
Rejowan Ahmed - 08.11.2022 10:57

Why are you so good? 💚💚💚

Ответить
SXsoft99
SXsoft99 - 07.11.2022 14:23

is Java secured?
I am going to leave a general answer "If the developer is bad at coding and doesn't care about securing their application NO", but then again there is a job market for people that are paid to look at the code and yell at those developers that they should not hardcode security keys inside the client app (for example: 2 years ago I was listening to a podcast of a lady that said she found hardcoded security keys inside android banking applications, with comments in the code "stop putting security keys in the code")
So to sum it up, most of the time the problem is between the chair and the screen

Ответить
Kevin Sada
Kevin Sada - 13.09.2022 18:12

Hello Povilas,
Great video! Just 1 question regarding the first example. What about the cases I have a WYSIWYG in my blog post and the user can enter a html? I am forced to escape it. what's the solution?

Ответить
vaibhavhalcyon
vaibhavhalcyon - 09.09.2022 16:51

gr8 video ,which i listen till date..

Ответить
Philip Serefoglou
Philip Serefoglou - 02.09.2022 18:22

Rate limit is a good option to negotiate delayed payments :P

Ответить
Mohammad reza Ghazy
Mohammad reza Ghazy - 31.07.2022 22:30

i wonder if you can make the same video for developers who use laravel just for API as a backend and tell us about security concerns we may face

Ответить
A Moktar
A Moktar - 20.06.2022 05:21

Thanks bro

Ответить
عبدالعزيز المخلافي
عبدالعزيز المخلافي - 31.05.2022 21:34

I always enjoy your content ♥️.

Ответить
Serdar Myradov
Serdar Myradov - 27.05.2022 06:34

thank you...

Ответить
aphelios chenik
aphelios chenik - 23.05.2022 22:15

never played a full tutorial video without x2 speed outside work. very good video i subed

Ответить
G5 STU - Station Master
G5 STU - Station Master - 15.05.2022 09:17

As someone that’s been using Laravel since v4.2, I love your content , straight to the point, no dithering , no BS - I hope you get your silver platter soon :)

Ответить
Kostic Nemanja
Kostic Nemanja - 25.04.2022 17:19

you sexy m.f. Pov. Great job !

Ответить
Ky Jovs
Ky Jovs - 08.02.2022 20:33

How to perform vulnerability assessment?

Ответить
Hermawan Safrin
Hermawan Safrin - 07.02.2022 11:32

Thank you sir, i think your videos is very usefull. Thanks for your dedication.

Ответить
Nodir Xakimov
Nodir Xakimov - 06.02.2022 10:28

I really appreciate your every single video. They are so helpful to me.

Ответить
Tim Koop
Tim Koop - 04.02.2022 18:31

Is it a mistake to add data in a migration, or should migrations only change the database structure? For example, we keep our translations in a database table. If we need another word translated, should we add this in a migration? Or should we use a seeder? Or something else?

Ответить
Emeka Timothy Iloba
Emeka Timothy Iloba - 03.02.2022 05:19

YOU WIll surely go beyond 200K subscribers Sir, you are really doing a great job. Thanks and God bless

Ответить
Emeka Timothy Iloba
Emeka Timothy Iloba - 03.02.2022 05:09

Wow this is very insightful sir. Thanks for sharing

Ответить
Eloquent
Eloquent - 02.02.2022 18:38

Thank you!

Ответить
Santo Rehman
Santo Rehman - 01.02.2022 16:49

What's the best secured way to upload laravel project in shared hosting?

Ответить
kiumars babolhavaeji
kiumars babolhavaeji - 31.01.2022 13:40

thank you

Ответить
MD ASIF IQBAL
MD ASIF IQBAL - 30.01.2022 19:16

Thank you so much for your video. Please make a video on passing {id} value in route. We are using direct id which is the primary key for the Post, Put method and Laravel also use the same in resource controller. Please make a video with this topic and security issues.

Ответить
hany sabry
hany sabry - 30.01.2022 10:55

Thanks Sir you helping so much .... i really appreciate it <3

Ответить
zzzyeP
zzzyeP - 30.01.2022 08:33

7 Mistakes beginners devs make :)

Ответить
Kira Yamato
Kira Yamato - 30.01.2022 07:30

Me who use REST API'S: 🤷

Ответить
MOHD ANAS
MOHD ANAS - 29.01.2022 18:38

Great

Ответить
NETWORKER BOWOFADE
NETWORKER BOWOFADE - 29.01.2022 18:26

pls I am used to csrf but with the invention of livewire, is it necessary again because I dint even bother to include it because you can submit form without even form elements using livewire.

Ответить
Loganathan Natarajan
Loganathan Natarajan - 29.01.2022 05:47

Thank you!

Ответить
Kaydot Origin
Kaydot Origin - 29.01.2022 05:31

Another: People using Raw DB queries and not binding parameters subsequently leading to an SQLi.

Ответить
Felipe Mello
Felipe Mello - 29.01.2022 01:34

Last week analyzing my apache log I found some requests to /.env, so make sure that your .env file is not public, you never will be 100% safe, so do your best

Ответить
Phoenix Edge
Phoenix Edge - 28.01.2022 18:47

Good stuff. Would you ever consider doing a course on security in Laravel, PHP, and Livewire, or even just more videos on it? It's a huge concern that I feel like doesn't get enough attention, and even as a mid-level developer and working with Laravel over 5 years, I'm not always sure how to be sure my code is 100% secure other than avoiding some of the obvious like you point out in this video. Like a good example of content you could cover is how supposedly we should be using UUIDs for our models, but it's not always clear the best way to do that or when to do that

Ответить
Mang Tri
Mang Tri - 28.01.2022 15:07

Nice info sir, thanks!

Ответить
Nabeel Yousaf Pasha
Nabeel Yousaf Pasha - 28.01.2022 12:26

Respect from Pakistan 🇵🇰
Rate Limiting is left from my side, all other stuff is my daily routine.

Ответить
Marvellous Ifezue
Marvellous Ifezue - 28.01.2022 11:36

But I feel like request except is also a security loophole

Ответить
Rob wolters
Rob wolters - 28.01.2022 10:59

I am using json in a crud app. Still a bit unsure about possible vulnerabilities. Do you have any information?

Ответить
Dawid Ruciński
Dawid Ruciński - 28.01.2022 02:26

Hello! Maybe you recording video on laravel Policy? How block any action in another user when user is not the same Group. Or how user can get only our post when he post another id in request. I have problem with this and no were information how do this. I have two model Clients and Users, Clientis Group amd have more users. Now when i send GET REQUEST id another client i can get users another client.

Ответить
Paulius Pagojus
Paulius Pagojus - 28.01.2022 00:29

Hello, Povilas I have a question. Lets say there is a blog post site and user can make a post that contains all those html tags like link, table and so on, how the content should be displayed if {!! $content !!} is a security issue? Should developer write a some code that checks if there are strings like <script> or <php or are there some other options?

Ответить
Muhammed RAFI A
Muhammed RAFI A - 27.01.2022 21:54

Hi povilaz....can you make one video about laravel project hosting in shared server, it's very helpful to all
Thanks in advance.

Ответить