Channel: LiveOverflow
Category: Education
Tags: cspbug bounty impactgoogle bug bountycorsmissing security headersliveoverflowbug bountycsrfgoogle vrpwithcredentialshow to hackexploit tutoriallive overflowhacking tutorialsecurity headersbugbountycors misconfigurationxsshstshttp headers
Description: In this video we talk about various HTTP headers that can improve or weaken the security of a site. And we discuss how serious they are in the context of Google's bug bounty program. Find the full playlist with videos for Google here: youtube.com/playlist?list=PLY-vqlMAnJ9bGoI82H1BB8BE4A8H2OCA- Chapters: 00:00 - Background Info 03:11 - Intro 03:53 - HTTP Security Header Overview 04:38 - Example #1: X-Frame-Options 06:43 - Example #2: Content-Security-Policy (CSP) 08:16 - Example #3: Strict-Transport-Security (HSTS) 10:44 - Example #4: Cross-Origin Resource Sharing (CORS) 13:12 - Example #5: Cookie Security Flags (HttpOnly) 14:25 - Summary 15:23 - Outro *advertisement because the video was originally produced for Google: bughunters.google.com/learn/videos/5956774821363712/bug-hunter-university-videos -=[ ā¤ļø Support ]=- ā per Video: patreon.com/join/liveoverflow ā per Month: youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w/join -=[ š Social ]=- ā Twitter: twitter.com/LiveOverflow ā Instagram: instagram.com/LiveOverflow ā Blog: liveoverflow.com ā Subreddit: reddit.com/r/LiveOverflow ā Facebook: facebook.com/LiveOverflow