OutSystems Security Specialization - Study Help Deck

Fábio Godinho
Fábio GodinhoOutSystems Reactive & Mobile Developer
SECURITY SPECIALIZATION
STUDY HELP DECK
Mandatory: name, username and pass
Authentication vs. Authorization
2
Security Specialization | Study Help Deck
Fábio Godinho | OutSystems ©
3
Security Specialization | Study Help Deck
Fábio Godinho | OutSystems ©
Authentication vs. Authorization
4
Security Specialization | Study Help Deck
Fábio Godinho | OutSystems ©
Roles
5
Security Specialization | Study Help Deck
Fábio Godinho | OutSystems ©
IT Users
6
Security Specialization | Study Help Deck
Fábio Godinho | OutSystems ©
IT Users
7
Security Specialization | Study Help Deck
Fábio Godinho | OutSystems ©
IT Users
User Permissions
Fábio Godinho | OutSystems © Security Specialization | Study Help Deck 8
Security configurations
9
Security Specialization | Study Help Deck
Fábio Godinho | OutSystems ©
Security configurations
10
Security Specialization | Study Help Deck
Fábio Godinho | OutSystems ©
Security configurations
11
Security Specialization | Study Help Deck
Fábio Godinho | OutSystems ©
Security configurations
12
Security Specialization | Study Help Deck
Fábio Godinho | OutSystems ©
Security configurations
13
Security Specialization | Study Help Deck
Fábio Godinho | OutSystems ©
CSP - Content Security Policy
14
Security Specialization | Study Help Deck
Fábio Godinho | OutSystems ©
CSP - Content Security Policy
15
Security Specialization | Study Help Deck
Fábio Godinho | OutSystems ©
CSP - Content Security Policy
16
Security Specialization | Study Help Deck
Fábio Godinho | OutSystems ©
Cookies
17
Security Specialization | Study Help Deck
Fábio Godinho | OutSystems ©
Applications Authentication
18
Security Specialization | Study Help Deck
Fábio Godinho | OutSystems ©
Secure Session Cookies
19
Security Specialization | Study Help Deck
Fábio Godinho | OutSystems ©
Secure Session Cookies
20
Security Specialization | Study Help Deck
Fábio Godinho | OutSystems ©
Authentication validations
21
Security Specialization | Study Help Deck
Fábio Godinho | OutSystems ©
Change the authentication provider
22
Security Specialization | Study Help Deck
Fábio Godinho | OutSystems ©
Change the Authentication plugin
23
Security Specialization | Study Help Deck
Fábio Godinho | OutSystems ©
Identity providers
24
Security Specialization | Study Help Deck
Fábio Godinho | OutSystems ©
Identity providers
25
Security Specialization | Study Help Deck
Fábio Godinho | OutSystems ©
Set multiple authentication providers
https://www.outsystems.com/blog/posts/multiple-authentication-providers/
26
Security Specialization | Study Help Deck
Fábio Godinho | OutSystems ©
SSL and Session Cookies
27
Security Specialization | Study Help Deck
Fábio Godinho | OutSystems ©
Security settings
28
Security Specialization | Study Help Deck
Fábio Godinho | OutSystems ©
Administrator accounts
29
Security Specialization | Study Help Deck
Fábio Godinho | OutSystems ©
Admin of the Users app
30
Security Specialization | Study Help Deck
Fábio Godinho | OutSystems ©
https://success.outsystems.com/documentation/11/managing_the_applications_lifecycle/manage_technical_debt/code_analysis_patterns/#security
31
Security Specialization | Study Help Deck
Fábio Godinho | OutSystems ©
Code analysis patterns
View state
32
Security Specialization | Study Help Deck
Fábio Godinho | OutSystems ©
Precautions
33
Security Specialization | Study Help Deck
Fábio Godinho | OutSystems ©
Precautions
34
Security Specialization | Study Help Deck
Fábio Godinho | OutSystems ©
Precautions
35
Security Specialization | Study Help Deck
Fábio Godinho | OutSystems ©
HSTS
36
Security Specialization | Study Help Deck
Fábio Godinho | OutSystems ©
HTTPS
37
Security Specialization | Study Help Deck
Fábio Godinho | OutSystems ©
HSTS & HTTPS
38
Security Specialization | Study Help Deck
Fábio Godinho | OutSystems ©
Precautions
39
Security Specialization | Study Help Deck
Fábio Godinho | OutSystems ©
SQL, HTML & Javascript Injection
40
Security Specialization | Study Help Deck
Fábio Godinho | OutSystems ©
Precautions
41
Security Specialization | Study Help Deck
Fábio Godinho | OutSystems ©
Internal User vs. External User
42
Security Specialization | Study Help Deck
Fábio Godinho | OutSystems ©
Providers & Authentication flow
If Active Directory OR LDAP:
- Login screen is the same BUT credentials are validated on
AD / LDAP server
- user is autom/ created in OS DB on the 1st successful
login without storing any password data
- first tries to authenticate user locally if exists in OS DB and
has a pasword defined!
If Integrated Windows Authentication:
- if user in same domain of the windows platform server,
authentication is against windows domain credentials
through browser and skips default login screen
43
Security Specialization | Study Help Deck
Fábio Godinho | OutSystems ©
Authentication flow
44
Security Specialization | Study Help Deck
Fábio Godinho | OutSystems ©
Authentication flow & User roles
45
Security Specialization | Study Help Deck
Fábio Godinho | OutSystems ©
Multi tenant
46
Security Specialization | Study Help Deck
Fábio Godinho | OutSystems ©
Persistency in Roles
47
Security Specialization | Study Help Deck
Fábio Godinho | OutSystems ©
Backoff for End Users
48
Security Specialization | Study Help Deck
Fábio Godinho | OutSystems ©
Backoff for IT Users
49
Security Specialization | Study Help Deck
Fábio Godinho | OutSystems ©
Envelope encryption
50
Security Specialization | Study Help Deck
Fábio Godinho | OutSystems ©
CIA Security triangle
51
Security Specialization | Study Help Deck
Fábio Godinho | OutSystems ©
NO
OWASP TOP
52
Security Specialization | Study Help Deck
Fábio Godinho | OutSystems ©
Cross Site Scripting - XSS
53
Security Specialization | Study Help Deck
Fábio Godinho | OutSystems ©
Session fixation attacks
54
Security Specialization | Study Help Deck
Fábio Godinho | OutSystems ©
PII and Sensitive Information
55
Security Specialization | Study Help Deck
Fábio Godinho | OutSystems ©
XML parsing
56
Security Specialization | Study Help Deck
Fábio Godinho | OutSystems ©
Authentication vs. Authorization
57
Security Specialization | Study Help Deck
Fábio Godinho | OutSystems ©
Insecure configurations
58
Security Specialization | Study Help Deck
Fábio Godinho | OutSystems ©
Deserialization
59
Security Specialization | Study Help Deck
Fábio Godinho | OutSystems ©
Vulnerability management
60
Security Specialization | Study Help Deck
Fábio Godinho | OutSystems ©
Logging
61
Security Specialization | Study Help Deck
Fábio Godinho | OutSystems ©
Key Store plugin & Man In The Middle Attack
62
Security Specialization | Study Help Deck
Fábio Godinho | OutSystems ©
Precautions
63
Security Specialization | Study Help Deck
Fábio Godinho | OutSystems ©
AppShield for MABS
64
Security Specialization | Study Help Deck
Fábio Godinho | OutSystems ©
Zero-Day Vulnerability
65
Security Specialization | Study Help Deck
Fábio Godinho | OutSystems ©
Sample questions
66
Security Specialization | Study Help Deck
Fábio Godinho | OutSystems ©
Sample questions
67
Security Specialization | Study Help Deck
Fábio Godinho | OutSystems ©
THANK YOU
in/fabiogod​
outsystems/profile
1 von 68

Recomendados

2007 Honda Crv Service Repair Manual von
2007 Honda Crv Service Repair Manual2007 Honda Crv Service Repair Manual
2007 Honda Crv Service Repair Manualhjnnsemmm
2.9K views26 Folien
Manual de Partes LF230 2007.pdf von
Manual de Partes LF230 2007.pdfManual de Partes LF230 2007.pdf
Manual de Partes LF230 2007.pdfPanchoArriaza
491 views310 Folien
Desordens fisiológicas e estresse von
Desordens fisiológicas e estresseDesordens fisiológicas e estresse
Desordens fisiológicas e estresseEleonoraBarbosaSanti
494 views45 Folien
Catálogo Trator 6145 j Jonh Deere von
Catálogo Trator 6145 j Jonh DeereCatálogo Trator 6145 j Jonh Deere
Catálogo Trator 6145 j Jonh DeereAndré Sá
22.4K views656 Folien
8.1 In Depth: New 64-bit Files and File Management von
8.1 In Depth: New 64-bit Files and File Management8.1 In Depth: New 64-bit Files and File Management
8.1 In Depth: New 64-bit Files and File ManagementRocket Software
209 views55 Folien
FARMTRAC AND FORD TRACTORS PARTS PHOTO CATALOG (S21-S25) von
FARMTRAC AND FORD TRACTORS PARTS PHOTO CATALOG (S21-S25)FARMTRAC AND FORD TRACTORS PARTS PHOTO CATALOG (S21-S25)
FARMTRAC AND FORD TRACTORS PARTS PHOTO CATALOG (S21-S25)Deepjot Rekhi
917 views21 Folien

Más contenido relacionado

Was ist angesagt?

Tecnologia de frutas: pectina von
Tecnologia de frutas: pectinaTecnologia de frutas: pectina
Tecnologia de frutas: pectinaAlvaro Galdos
12.3K views29 Folien
Processamento de produtos de origem vegetal von
Processamento de produtos de origem vegetalProcessamento de produtos de origem vegetal
Processamento de produtos de origem vegetalsaraerthal
21.9K views80 Folien
Catalogo conversão de rolamentos von
Catalogo conversão  de  rolamentosCatalogo conversão  de  rolamentos
Catalogo conversão de rolamentoscardans
98.3K views7 Folien
Mitsubishi forklift spare parts manufacturer from zefeng 8618721729659 von
Mitsubishi forklift spare parts manufacturer from zefeng 8618721729659Mitsubishi forklift spare parts manufacturer from zefeng 8618721729659
Mitsubishi forklift spare parts manufacturer from zefeng 8618721729659chu aimee
723 views17 Folien
Classificação atualizada von
Classificação atualizadaClassificação atualizada
Classificação atualizadaAndré Sá
1.8K views7 Folien
Catalogo Valmet 60 id von
Catalogo Valmet 60 idCatalogo Valmet 60 id
Catalogo Valmet 60 idCatalogo Fácil Agro Mecânica Tatuí
32.3K views307 Folien

Was ist angesagt?(20)

Tecnologia de frutas: pectina von Alvaro Galdos
Tecnologia de frutas: pectinaTecnologia de frutas: pectina
Tecnologia de frutas: pectina
Alvaro Galdos12.3K views
Processamento de produtos de origem vegetal von saraerthal
Processamento de produtos de origem vegetalProcessamento de produtos de origem vegetal
Processamento de produtos de origem vegetal
saraerthal21.9K views
Catalogo conversão de rolamentos von cardans
Catalogo conversão  de  rolamentosCatalogo conversão  de  rolamentos
Catalogo conversão de rolamentos
cardans98.3K views
Mitsubishi forklift spare parts manufacturer from zefeng 8618721729659 von chu aimee
Mitsubishi forklift spare parts manufacturer from zefeng 8618721729659Mitsubishi forklift spare parts manufacturer from zefeng 8618721729659
Mitsubishi forklift spare parts manufacturer from zefeng 8618721729659
chu aimee723 views
Classificação atualizada von André Sá
Classificação atualizadaClassificação atualizada
Classificação atualizada
André Sá1.8K views
Mecanismo de Ação dos Fungicidas .pptx von Geagra UFG
Mecanismo de Ação dos Fungicidas .pptxMecanismo de Ação dos Fungicidas .pptx
Mecanismo de Ação dos Fungicidas .pptx
Geagra UFG2.2K views
FARMTRAC AND FORD TRACTORS PARTS PHOTO CATALOG (S26-S30) von Deepjot Rekhi
FARMTRAC AND FORD TRACTORS PARTS PHOTO CATALOG (S26-S30)FARMTRAC AND FORD TRACTORS PARTS PHOTO CATALOG (S26-S30)
FARMTRAC AND FORD TRACTORS PARTS PHOTO CATALOG (S26-S30)
Deepjot Rekhi1.3K views
ENTRAVES FITOSSANITÁRIOS NA AGRICULTURA von Geagra UFG
ENTRAVES FITOSSANITÁRIOS NA AGRICULTURAENTRAVES FITOSSANITÁRIOS NA AGRICULTURA
ENTRAVES FITOSSANITÁRIOS NA AGRICULTURA
Geagra UFG1.3K views
Tratos Culturais: Aplicação de Fungicidas von Geagra UFG
Tratos Culturais: Aplicação de FungicidasTratos Culturais: Aplicação de Fungicidas
Tratos Culturais: Aplicação de Fungicidas
Geagra UFG1.8K views
Tecnologia de-aplicacao-de-herbicidas- von Marcos Ferreira
Tecnologia de-aplicacao-de-herbicidas-Tecnologia de-aplicacao-de-herbicidas-
Tecnologia de-aplicacao-de-herbicidas-
Marcos Ferreira6.6K views
Catalogo Plantadeira Pl 710 rf 712 e 716 von André Sá
Catalogo Plantadeira Pl 710 rf 712 e 716Catalogo Plantadeira Pl 710 rf 712 e 716
Catalogo Plantadeira Pl 710 rf 712 e 716
André Sá3.9K views
Processos de transformação de alimentos von UFPE
Processos de transformação de alimentosProcessos de transformação de alimentos
Processos de transformação de alimentos
UFPE1K views
Catálago de rolamentos de-rolos conicos SNR von André Sá
Catálago de rolamentos de-rolos conicos SNRCatálago de rolamentos de-rolos conicos SNR
Catálago de rolamentos de-rolos conicos SNR
André Sá12.3K views
MANCOZEBE, MULTISSÍTIO E RESISTÊNCIA von Geagra UFG
MANCOZEBE, MULTISSÍTIO E RESISTÊNCIAMANCOZEBE, MULTISSÍTIO E RESISTÊNCIA
MANCOZEBE, MULTISSÍTIO E RESISTÊNCIA
Geagra UFG6.1K views

Similar a OutSystems Security Specialization - Study Help Deck

Keeping your collaboration safe while working remotely von
Keeping your collaboration safe while working remotelyKeeping your collaboration safe while working remotely
Keeping your collaboration safe while working remotelyCisco Webex
414 views39 Folien
Architecture OutSystems Security Specialization - Study Help Deck von
Architecture  OutSystems Security Specialization - Study Help DeckArchitecture  OutSystems Security Specialization - Study Help Deck
Architecture OutSystems Security Specialization - Study Help DeckFábio Godinho
36 views70 Folien
FIDO Alliance Webinar: Intuit's Journey with FIDO Authentication von
FIDO Alliance Webinar: Intuit's Journey with FIDO AuthenticationFIDO Alliance Webinar: Intuit's Journey with FIDO Authentication
FIDO Alliance Webinar: Intuit's Journey with FIDO AuthenticationFIDO Alliance
8.3K views15 Folien
FIDO & PSD2 – Achieving Strong Customer Authentication Compliance von
FIDO & PSD2 – Achieving Strong Customer Authentication ComplianceFIDO & PSD2 – Achieving Strong Customer Authentication Compliance
FIDO & PSD2 – Achieving Strong Customer Authentication ComplianceFIDO Alliance
2.7K views32 Folien
OutSystems Front End Specialization - Study Help Deck von
OutSystems Front End Specialization - Study Help DeckOutSystems Front End Specialization - Study Help Deck
OutSystems Front End Specialization - Study Help DeckFábio Godinho
3.4K views45 Folien
2018-10-23 2B - a deep dive into Microsoft 365 security - Muditha Chathuranga von
2018-10-23 2B - a deep dive into Microsoft 365 security - Muditha Chathuranga2018-10-23 2B - a deep dive into Microsoft 365 security - Muditha Chathuranga
2018-10-23 2B - a deep dive into Microsoft 365 security - Muditha ChathurangaaOS Community
100 views57 Folien

Similar a OutSystems Security Specialization - Study Help Deck(20)

Keeping your collaboration safe while working remotely von Cisco Webex
Keeping your collaboration safe while working remotelyKeeping your collaboration safe while working remotely
Keeping your collaboration safe while working remotely
Cisco Webex414 views
Architecture OutSystems Security Specialization - Study Help Deck von Fábio Godinho
Architecture  OutSystems Security Specialization - Study Help DeckArchitecture  OutSystems Security Specialization - Study Help Deck
Architecture OutSystems Security Specialization - Study Help Deck
Fábio Godinho36 views
FIDO Alliance Webinar: Intuit's Journey with FIDO Authentication von FIDO Alliance
FIDO Alliance Webinar: Intuit's Journey with FIDO AuthenticationFIDO Alliance Webinar: Intuit's Journey with FIDO Authentication
FIDO Alliance Webinar: Intuit's Journey with FIDO Authentication
FIDO Alliance8.3K views
FIDO & PSD2 – Achieving Strong Customer Authentication Compliance von FIDO Alliance
FIDO & PSD2 – Achieving Strong Customer Authentication ComplianceFIDO & PSD2 – Achieving Strong Customer Authentication Compliance
FIDO & PSD2 – Achieving Strong Customer Authentication Compliance
FIDO Alliance2.7K views
OutSystems Front End Specialization - Study Help Deck von Fábio Godinho
OutSystems Front End Specialization - Study Help DeckOutSystems Front End Specialization - Study Help Deck
OutSystems Front End Specialization - Study Help Deck
Fábio Godinho3.4K views
2018-10-23 2B - a deep dive into Microsoft 365 security - Muditha Chathuranga von aOS Community
2018-10-23 2B - a deep dive into Microsoft 365 security - Muditha Chathuranga2018-10-23 2B - a deep dive into Microsoft 365 security - Muditha Chathuranga
2018-10-23 2B - a deep dive into Microsoft 365 security - Muditha Chathuranga
aOS Community100 views
Cisco ISE BYOD Prescriptive Deployment Guide - Cisco Community.pdf von dimax2011
Cisco ISE BYOD Prescriptive Deployment Guide - Cisco Community.pdfCisco ISE BYOD Prescriptive Deployment Guide - Cisco Community.pdf
Cisco ISE BYOD Prescriptive Deployment Guide - Cisco Community.pdf
dimax201154 views
Alfresco Virtual DevCon 2020 - Security First! von Jason Jolley
Alfresco Virtual DevCon 2020 - Security First!Alfresco Virtual DevCon 2020 - Security First!
Alfresco Virtual DevCon 2020 - Security First!
Jason Jolley54 views
FIDO Specifications Overview von FIDO Alliance
FIDO Specifications OverviewFIDO Specifications Overview
FIDO Specifications Overview
FIDO Alliance1.3K views
M&A security - E-crime Congress 2017 von EQS Group
M&A security - E-crime Congress 2017M&A security - E-crime Congress 2017
M&A security - E-crime Congress 2017
EQS Group430 views
AD-Bridge-course.pdf von neoalt
AD-Bridge-course.pdfAD-Bridge-course.pdf
AD-Bridge-course.pdf
neoalt2 views
Pg presentation for steph von Kjohnson33
Pg presentation for stephPg presentation for steph
Pg presentation for steph
Kjohnson33269 views
FIDO2 : vers la fin des mots de passe ? - Par Arnaud Jumelet von Identity Days
FIDO2 : vers la fin des mots de passe ? - Par Arnaud JumeletFIDO2 : vers la fin des mots de passe ? - Par Arnaud Jumelet
FIDO2 : vers la fin des mots de passe ? - Par Arnaud Jumelet
Identity Days473 views
Overview of FIDO Security Requirements and Certifications von FIDO Alliance
Overview of FIDO Security Requirements and CertificationsOverview of FIDO Security Requirements and Certifications
Overview of FIDO Security Requirements and Certifications
FIDO Alliance1.4K views
FIDO Authentication Technical Overview von FIDO Alliance
FIDO Authentication Technical OverviewFIDO Authentication Technical Overview
FIDO Authentication Technical Overview
FIDO Alliance448 views
FIDO Authentication Technical Overview von FIDO Alliance
FIDO Authentication Technical OverviewFIDO Authentication Technical Overview
FIDO Authentication Technical Overview
FIDO Alliance4.1K views
Fido Technical Overview von FIDO Alliance
Fido Technical OverviewFido Technical Overview
Fido Technical Overview
FIDO Alliance1.9K views
October 2022 CIAOPS Need to Know Webinar von Robert Crane
October 2022 CIAOPS Need to Know WebinarOctober 2022 CIAOPS Need to Know Webinar
October 2022 CIAOPS Need to Know Webinar
Robert Crane479 views

Último

Generic or specific? Making sensible software design decisions von
Generic or specific? Making sensible software design decisionsGeneric or specific? Making sensible software design decisions
Generic or specific? Making sensible software design decisionsBert Jan Schrijver
6 views60 Folien
HarshithAkkapelli_Presentation.pdf von
HarshithAkkapelli_Presentation.pdfHarshithAkkapelli_Presentation.pdf
HarshithAkkapelli_Presentation.pdfharshithakkapelli
11 views16 Folien
Unlocking the Power of AI in Product Management - A Comprehensive Guide for P... von
Unlocking the Power of AI in Product Management - A Comprehensive Guide for P...Unlocking the Power of AI in Product Management - A Comprehensive Guide for P...
Unlocking the Power of AI in Product Management - A Comprehensive Guide for P...NimaTorabi2
12 views17 Folien
2023-November-Schneider Electric-Meetup-BCN Admin Group.pptx von
2023-November-Schneider Electric-Meetup-BCN Admin Group.pptx2023-November-Schneider Electric-Meetup-BCN Admin Group.pptx
2023-November-Schneider Electric-Meetup-BCN Admin Group.pptxanimuscrm
15 views19 Folien
WebAssembly von
WebAssemblyWebAssembly
WebAssemblyJens Siebert
51 views18 Folien
Unleash The Monkeys von
Unleash The MonkeysUnleash The Monkeys
Unleash The MonkeysJacob Duijzer
8 views28 Folien

Último(20)

Generic or specific? Making sensible software design decisions von Bert Jan Schrijver
Generic or specific? Making sensible software design decisionsGeneric or specific? Making sensible software design decisions
Generic or specific? Making sensible software design decisions
Unlocking the Power of AI in Product Management - A Comprehensive Guide for P... von NimaTorabi2
Unlocking the Power of AI in Product Management - A Comprehensive Guide for P...Unlocking the Power of AI in Product Management - A Comprehensive Guide for P...
Unlocking the Power of AI in Product Management - A Comprehensive Guide for P...
NimaTorabi212 views
2023-November-Schneider Electric-Meetup-BCN Admin Group.pptx von animuscrm
2023-November-Schneider Electric-Meetup-BCN Admin Group.pptx2023-November-Schneider Electric-Meetup-BCN Admin Group.pptx
2023-November-Schneider Electric-Meetup-BCN Admin Group.pptx
animuscrm15 views
Dapr Unleashed: Accelerating Microservice Development von Miroslav Janeski
Dapr Unleashed: Accelerating Microservice DevelopmentDapr Unleashed: Accelerating Microservice Development
Dapr Unleashed: Accelerating Microservice Development
Miroslav Janeski10 views
Copilot Prompting Toolkit_All Resources.pdf von Riccardo Zamana
Copilot Prompting Toolkit_All Resources.pdfCopilot Prompting Toolkit_All Resources.pdf
Copilot Prompting Toolkit_All Resources.pdf
Riccardo Zamana10 views
DSD-INT 2023 3D hydrodynamic modelling of microplastic transport in lakes - J... von Deltares
DSD-INT 2023 3D hydrodynamic modelling of microplastic transport in lakes - J...DSD-INT 2023 3D hydrodynamic modelling of microplastic transport in lakes - J...
DSD-INT 2023 3D hydrodynamic modelling of microplastic transport in lakes - J...
Deltares12 views
360 graden fabriek von info33492
360 graden fabriek360 graden fabriek
360 graden fabriek
info33492122 views
Fleet Management Software in India von Fleetable
Fleet Management Software in India Fleet Management Software in India
Fleet Management Software in India
Fleetable11 views
Headless JS UG Presentation.pptx von Jack Spektor
Headless JS UG Presentation.pptxHeadless JS UG Presentation.pptx
Headless JS UG Presentation.pptx
Jack Spektor8 views

OutSystems Security Specialization - Study Help Deck