World Congress 2024 Aug 20, 2024 Session details

Programming secure C#/.NET Applications: Dos & Don'ts

Sebastian Leuer

Did you know AI frequently injects deprecated crypto classes into C# code? Master secure .NET architecture and strict parameter validation to prevent critical system compromise.

Pause
Mute Enter Fullscreen
#1 about 3 min

Introduction to speaker and software security concepts

How static code analysis tooling and security training help developers eliminate false positives and build more secure .NET applications.

#2 about 5 min

Security risks of AI based code generation

Why relying on AI to generate cryptographic logic leads to deprecated APIs and insecure practices like missing special characters.

#3 about 11 min

Preventing visual spoofing and Unicode handling vulnerabilities

How visual spoofing and improper Unicode normalization can bypass validation logic and misroute sensitive platform data.

#4 about 4 min

Demonstrating and preventing SQL injection in .NET

Modifying inline SQL statements to use parameterized queries prevents malicious database manipulation by untrusted user input.

#5 about 4 min

Preventing command injection during system process execution

Safely passing user input to system processes using the ArgumentList property in .NET Core prevents arbitrary code execution.

#6 about 6 min

Securing file upload features against path traversal

Enforcing bounding sandbox directories and validating absolute paths stops attackers from using relative references to rewrite system files.

#7 about 4 min

Securing JSON and XML parsing against exploits

Disabling automatic type handling and DTD processing in parsers mitigates arbitrary code execution and system crashes from malformed inputs.

Matching moments

4:02 min

Preventing application outages caused by unvetted AI generated code

Chris Heilmann +2 · LIVE

4:15 min

Security vulnerabilities introduced by frictionless AI code generation

Angie Jones Angie Jones +3 · LIVE

2:19 min

Security vulnerabilities hidden in elegant syntax

Chris Heilmann +2 · LIVE

2:59 min

Building a vulnerable application for security testing

Malte Lantin Malte Lantin +1 · WWC Europe 2026

1:06 min

Addressing security flaws in AI-generated code

Balázs Kiss · WWC 2023

2:05 min

The impact and risks of AI generated code

Chris Heilmann · LIVE

Upcoming sessions on this topic

Open session

World Congress 2026 North America

The Things Your AI Isn't Telling You

Desmond Lamptey

Lead Software Engineer @ Capital One

Desmond Lamptey
Open session

World Congress 2026 North America

SecurePrompt: Building a Pre-Flight Security Layer for Agentic AI

Ravi Sastry Kadali

AI/ML Engineer at General Motors

Ravi Sastry Kadali
Open session

World Congress 2026 North America

Don’t kill my Vibes - Simple Steps to Stay Secure when Vibe Coding

Isaac Evans

Co-founder & CEO of Semgrep

Isaac Evans
Open session

World Congress 2026 North America

Secure-by-Inclusion: Preventing Accessibility Barriers from Becoming Security Vulnerabilities

Radostina (Ina) Tsvetkova

Norwegian Directorate of Labour and Welfare (NAV), Senior Advisor in Digital Accessibility and Inclusive Design

Radostina (Ina) Tsvetkova
Open session

World Congress 2026 North America

Responsible AI Architecture with Zero Trust Agents

Ashok Prakash

Staff ML Engineer at Apple

Ashok Prakash
Open session

World Congress 2026 North America

Red Teaming Your LLM App -- A Hands-On Threat Model You Can Reuse

Saloni Garg

Senior ML Engineer at Adobe

Saloni Garg