Session 10: Security in Web Development

Université de Toulon

LIS UMR CNRS 7020

2026-10-05

Session 10: Security in Web Development

Session Structure

  • Introduction to Web Security
  • Common Web Security Threats
  • Best Practices for Securing Web Applications
  • Handling Passwords Securely
  • Introduction to Tokens and Security Keys
  • Hands-on Project: Implementing Security Measures

Introduction to Web Security

What is Web Security?

  • The practice of protecting websites and web applications from cyber threats.
  • Ensures the confidentiality, integrity, and availability of data.

Importance of Web Security

  • Protects sensitive user data.
  • Maintains user trust and application reputation.
  • Prevents financial losses and legal issues.

Common Web Security Threats

Cross-Site Scripting (XSS)

  • Definition: An attack where malicious scripts are injected into trusted websites.
  • Impact: Can steal user data, hijack sessions, and deface websites.
  • Prevention:
    • Validate and sanitize user inputs.
    • Use Content Security Policy (CSP) headers.
  • Example: A comment section on a blog where an attacker injects a script to steal cookies.

SQL Injection

  • Definition: An attack where malicious SQL queries are injected into input fields.
  • Impact: Can manipulate databases, retrieve sensitive data, and delete records.
  • Prevention:
    • Use prepared statements and parameterized queries.
    • Validate and sanitize user inputs.
  • Example: A login form where an attacker inputs a SQL query to bypass authentication.

Cross-Site Request Forgery (CSRF)

  • Definition: An attack where unauthorized commands are transmitted from a user that the web application trusts.
  • Impact: Can perform actions on behalf of authenticated users without their consent.
  • Prevention:
    • Use anti-CSRF tokens.
    • Implement same-site cookies.
  • Example: A malicious email link that triggers a fund transfer from a user’s bank account.

Man-in-the-Middle (MITM) Attacks

  • Definition: An attack where a third party intercepts and potentially alters communication between two parties.
  • Impact: Can steal sensitive data and inject malicious content.
  • Prevention:
    • Use HTTPS to encrypt data in transit.
    • Implement secure communication protocols.
  • Example: An attacker intercepting data between a user and an online shopping site to steal credit card information.

Best Practices for Securing Web Applications

Use HTTPS

  • Encrypts data transmitted between the client and server.
  • Prevents eavesdropping and tampering.
  • Example: A secure e-commerce website using HTTPS to protect customer transactions.

Secure Authentication

  • Use strong, unique passwords.
  • Implement multi-factor authentication (MFA).
  • Store passwords securely using hashing algorithms.
  • Example: An online banking system requiring MFA for account access.

Regular Security Audits

  • Conduct regular security assessments and penetration testing.
  • Identify and fix vulnerabilities promptly.
  • Example: A company scheduling quarterly security audits to ensure their web application is secure.

Keep Software Up-to-Date

  • Regularly update web servers, frameworks, and libraries.
  • Apply security patches as soon as they are released.
  • Example: A content management system (CMS) applying the latest security patches to prevent exploits.

Input Validation and Sanitization

  • Validate and sanitize all user inputs to prevent injection attacks.
  • Use libraries and frameworks that provide built-in security features.
  • Example: A web form that validates email addresses to prevent malicious input.

Secure Session Management

  • Use secure cookies with the HttpOnly and Secure flags.
  • Implement session timeouts and re-authentication for sensitive actions.
  • Example: An online shopping cart that expires after a period of inactivity to protect user data.

Handling Passwords Securely

Password Storage

  • Hashing: Convert passwords into a fixed-length string of characters using a hashing algorithm.
    • Use strong hashing algorithms like bcrypt, Argon2, or PBKDF2.
    • Add a unique salt to each password before hashing to prevent rainbow table attacks.
  • Never store plain text passwords: Always store hashed passwords in the database.
  • Example: A social media platform hashing user passwords before storing them in the database.

Password Policies

  • Strong Passwords: Enforce the use of strong passwords (e.g., minimum length, mix of characters).
  • Password Expiry: Implement policies to require users to change passwords periodically.
  • Account Lockout: Lock accounts after a certain number of failed login attempts to prevent brute force attacks.
  • Example: An enterprise application requiring employees to change their passwords every 90 days.

Introduction to Tokens and Security Keys

Tokens

  • Definition: Tokens are used to authenticate and authorize users without requiring them to re-enter credentials.
  • Types of Tokens:
    • Session Tokens: Used to maintain user sessions.
    • JWT (JSON Web Tokens): A compact, URL-safe means of representing claims to be transferred between two parties.
  • Usage:
    • Tokens are generated upon successful authentication and sent to the client.
    • The client includes the token in subsequent requests to access protected resources.
    • Tokens should be stored securely (e.g., in HTTP-only cookies).
  • Example: A web application using JWTs to manage user sessions and authorize API requests.

Security Keys

  • Definition: Security keys are used to sign and verify tokens, ensuring their integrity and authenticity.
  • Types of Keys:
    • Symmetric Keys: The same key is used for both signing and verification.
    • Asymmetric Keys: A pair of keys (public and private) is used; one key signs the token, and the other verifies it.
  • Usage:
    • Use strong, randomly generated keys.
    • Rotate keys periodically to enhance security.
  • Example: An API service using asymmetric keys to sign and verify JWTs for secure communication.

Hands-on Project: Implementing Security Measures

Project Goals

  • Secure a web application by implementing various security measures.
  • Protect the application from common web security threats.

Steps

  1. Set Up HTTPS:
    • Obtain an SSL/TLS certificate from a trusted Certificate Authority (CA).
    • Configure your web server to use HTTPS.
  2. Implement Secure Authentication:
    • Use a robust authentication mechanism.
    • Enable multi-factor authentication (MFA) for added security.
  3. Validate and Sanitize User Inputs:
    • Ensure all user inputs are validated and sanitized to prevent injection attacks.
  4. Use Prepared Statements:
    • Use prepared statements and parameterized queries to prevent SQL injection.
    • Ensure all database interactions are secure.
  5. Add Anti-CSRF Tokens:
    • Implement anti-CSRF tokens to protect against CSRF attacks.
    • Validate the tokens on the server side.
  6. Handle Passwords Securely:
    • Hash passwords using a strong hashing algorithm before storing them in the database.
    • Implement strong password policies and account lockout mechanisms.
  7. Implement Token-Based Authentication:
    • Use tokens for stateless authentication.
    • Securely store and manage tokens and security keys.
  8. Conduct a Security Audit:
    • Perform a security audit to identify and fix vulnerabilities.
    • Use automated tools to assist in the audit process.

Additional Tips

  • Stay Informed: Keep up with the latest security trends and vulnerabilities.
  • Community Support: Utilize community forums and support channels for troubleshooting.
  • Continuous Learning: Regularly attend security workshops and training sessions.

This lecture provides a comprehensive introduction to web security, highlighting common threats and best practices for securing web applications. It includes a hands-on project to help students implement security measures in a practical context. Feel free to adjust the content based on your course duration and student experience.