The Art of exploiting Injection flaws@ Black Hat Vegas 2013

Viewing 5 reply threads
  • Author
    Posts
    • #8281
      notsosecure
      Participant

      The popular course, The Art of Exploiting Injection Flaws will return to Black Hat Las Vegas in July 2013. The OWASP top 10 2013 RC has retained Injection flaw as still the top threat to web applications. Learn advanced SQLI, as well as some new, neat and ridiculous hacks in LDAP, XPATH, XXE, HQLI, direct code (ala RoR flaw) etc.

      More details here:

      http://blackhat.com/us-13/training/the-art-of-exploiting-injection-flaws.html

      Identify, extract, escalate, execute.. need we say more?

    • #52179
      MaXe
      Participant

      It’s a very good course, I recently some most of it, he knows his stuff (and beyond), no questions about that  ;D

    • #52180
      notsosecure
      Participant

      Thanks Maxe,

      Just for the benefit for anyone who is not familiar with course content, the topics which might be of interest to them which the course covers:

      Oracle SQLI- how do execute code, how to do priv esc from web app, OOB
      extraction might be of interest to you. Examples of burp pro missing
      SQLI. Injection in order by/group by, 2nd order injection etc.
      Stuff on XPATH is pretty awesome. I will show a new attack with which
      you can not just read any arbitrary XML file on system but any file
      with any extension.
      LDAP- some really good example of auth bypass and blind ldap tool.
      XXE- not too new stuff but good pointer on where to look for these.
      Direct code injection- examples of recent ruby on rail and other
      framework issues such as expression query language injection etc

      Hope to meet some of the fellow ethicalhacker members at Black hat!

      Sid

    • #52181
      notsosecure
      Participant

      here is a small podcast featuring me on pauldotcom, which gives an insight into the course 🙂

      http://www.ustream.tv/recorded/31958833

    • #52182
      Triban
      Participant

      Just listened to that on the way home today, interesting stuff.

    • #52183
      notsosecure
      Participant
Viewing 5 reply threads
  • You must be logged in to reply to this topic.

Copyright ©2020 Caendra, Inc.

Contact Us

Thoughts, suggestions, issues? Send us an email, and we'll get back to you.

Sending

Sign in with Caendra

Forgot password?Sign up

Forgot your details?