The Art of exploiting Injection flaws@ Black Hat Vegas 2013

Viewing 5 reply threads
  • Author
    • #8281

      The popular course, The Art of Exploiting Injection Flaws will return to Black Hat Las Vegas in July 2013. The OWASP top 10 2013 RC has retained Injection flaw as still the top threat to web applications. Learn advanced SQLI, as well as some new, neat and ridiculous hacks in LDAP, XPATH, XXE, HQLI, direct code (ala RoR flaw) etc.

      More details here:

      Identify, extract, escalate, execute.. need we say more?

    • #52179

      It’s a very good course, I recently some most of it, he knows his stuff (and beyond), no questions about that  ;D

    • #52180

      Thanks Maxe,

      Just for the benefit for anyone who is not familiar with course content, the topics which might be of interest to them which the course covers:

      Oracle SQLI- how do execute code, how to do priv esc from web app, OOB
      extraction might be of interest to you. Examples of burp pro missing
      SQLI. Injection in order by/group by, 2nd order injection etc.
      Stuff on XPATH is pretty awesome. I will show a new attack with which
      you can not just read any arbitrary XML file on system but any file
      with any extension.
      LDAP- some really good example of auth bypass and blind ldap tool.
      XXE- not too new stuff but good pointer on where to look for these.
      Direct code injection- examples of recent ruby on rail and other
      framework issues such as expression query language injection etc

      Hope to meet some of the fellow ethicalhacker members at Black hat!


    • #52181

      here is a small podcast featuring me on pauldotcom, which gives an insight into the course 🙂

    • #52182

      Just listened to that on the way home today, interesting stuff.

    • #52183
Viewing 5 reply threads
  • You must be logged in to reply to this topic.

Copyright ©2021 Caendra, Inc.

Contact Us

Thoughts, suggestions, issues? Send us an email, and we'll get back to you.


Sign in with Caendra

Forgot password?Sign up

Forgot your details?