The HaaHa Show: Microsoft ASP.NET MVC Security with Haack and Hanselman

Get Microsoft Silverlight

Join Phil Haack and Scott Hanselman for this dynamic and unusual security session. The HaaHa brothers take turns implementing features on an ASP.NET MVC website. Scott writes a feature, and Phil exploits it and hacks into the system. We analyze and discuss the exploits live on stage and then close them one by one. Learn about XSS, CSRF, JSON Hijacking and more. Is *your* site safe from the Haack?

11 Comments

+ Add comment
  • Zachary Scott (gravatar)

    Zachary Scott said
    Feb 18 2010

    It would be really good to put these ideas in to automated testing.

  • Keith (gravatar)

    Keith said
    Mar 8 2010

    Who likes to rock the party? Phil Haack and Scott Hanselman like to rock the party!

  • Chris (gravatar)

    Chris said
    Mar 10 2010

    Great title for this presentation. The dynamic duo teaming up to present this topic should make for a very entertaining and informative presentation. I'm bummed that I will miss MIX this year :(

  • really?

  • mike j (gravatar)

    mike j said
    2 days ago

    This should be really good. Anyone know if this will make it to http://live.visitmix.com?

    I am stuck in Toronto doing a release but would love to see this talk somehow.

  • Prepare to get haacked!!!

  • I'm so excited :)
    It will be so good.

  • Ronald Garlit  (gravatar)

    Ronald Garlit said
    1 day ago

    Will there be a recording on MSDN?

    We are working on our pilots and testing of MVC Framework to determine it's place within our company.

    Security Practices specific to MVC Framework is one of the areas I'm looking for information on.


  • Is true that winpho 7 wont have copy and paste? wow thats sucks, maybe android is actually better?

    http://www.engadget.com/2010/03/16/windows-phone-7-series-wont-have-copy-and-paste/

  • Roger (gravatar)

    Roger said
    3 hours ago

    I get a media failure when viewing the video. Anyone else getting this?
    Roger

  • Kevin (gravatar)

    Kevin said
    1 hour ago

    I get media failure too, around 15min into the video. The download fails on that spot too.

    to bad =(

Mrs. Gravatar (gravatar)

<-- It's a gravatar