site image
Andrew Lock avatar

Andrew Lock

Security
  1. Loading...
  2. Sponsored by Dometrain Courses—Get 30% off Dometrain Pro with code ANDREW30 and access the best courses for .NET Developers

    30% off with code ANDREW30 on Dometrain Pro
  3. ASP.NET Core in Action, Third Edition

    My new book ASP.NET Core in Action, Third Edition is available now! It supports .NET 7.0, and is available as an eBook or paperback.

  4. Banner image for Cross-Origin-Resource-Policy: preventing hotlinking and XSSI attacks

    Cross-Origin-Resource-Policy: preventing hotlinking and XSSI attacks

    Understanding cross-origin security headers - Part 2

    In this post I describe how to use the Cross-Origin-Resource-Policy to block cross-origin requests that would normally be allowed, such as in <img> tags…

     in  SecurityASP.NET CoreCORS
  5. Banner image for Cross-Origin-Opener-Policy: preventing attacks from popups

    Cross-Origin-Opener-Policy: preventing attacks from popups

    Understanding cross-origin security headers - Part 1

    In this post I describe the vulnerabilities in window.opener and window.open() and how to protect yourself with Cross-Origin-Opener-Policy…

     in  SecurityASP.NET Core
  6. Banner image for Understanding cross-origin security headers

    Understanding cross-origin security headers

    In this series I look at some of the security headers you can apply to your applications to enhance your security when interacting with cross-origin resources…

     in  ASP.NET CoreSecurityCORS
  7. Banner image for Major updates to NetEscapades.​AspNetCore.​SecurityHeaders

    Major updates to NetEscapades.​AspNetCore.​SecurityHeaders

    In this post I describe the recent major changes to NetEscapades.AspNetCore.SecurityHeaders, a NuGet package for adding security headers to your apps.…

     in  ASP.NET CoreMiddlewareSecurity
  8. Banner image for Avoiding CDN supply-chain attacks with Subresource Integrity (SRI)

    Avoiding CDN supply-chain attacks with Subresource Integrity (SRI)

    In this post I discus the recent pollyfill.io supply-chain attack and describe how to protect against similar attacks using Subresource Integrity (SRI)…

     in  SecurityFront End
  9. Banner image for Configuring HTTPS using a custom TLS certificate with Netlify and Cloudflare

    Configuring HTTPS using a custom TLS certificate with Netlify and Cloudflare

    In this post I describe an HTTPS issue when using Cloudflare in front of Netlify, and how to create a custom TLS certificate for full encryption.…

     in  HostingSecurityDevOps
Andrew Lock | .Net Escapades
Want an email when
there's new posts?