March 5, 2013 at 1:23 pm #8281
The popular course, The Art of Exploiting Injection Flaws will return to Black Hat Las Vegas in July 2013. The OWASP top 10 2013 RC has retained Injection flaw as still the top threat to web applications. Learn advanced SQLI, as well as some new, neat and ridiculous hacks in LDAP, XPATH, XXE, HQLI, direct code (ala RoR flaw) etc.
More details here:
Identify, extract, escalate, execute.. need we say more?
March 5, 2013 at 2:37 pm #52179MaXeParticipant
It’s a very good course, I recently some most of it, he knows his stuff (and beyond), no questions about that ;D
March 6, 2013 at 1:36 pm #52180
Just for the benefit for anyone who is not familiar with course content, the topics which might be of interest to them which the course covers:
Oracle SQLI- how do execute code, how to do priv esc from web app, OOB
extraction might be of interest to you. Examples of burp pro missing
SQLI. Injection in order by/group by, 2nd order injection etc.
Stuff on XPATH is pretty awesome. I will show a new attack with which
you can not just read any arbitrary XML file on system but any file
with any extension.
LDAP- some really good example of auth bypass and blind ldap tool.
XXE- not too new stuff but good pointer on where to look for these.
Direct code injection- examples of recent ruby on rail and other
framework issues such as expression query language injection etc
Hope to meet some of the fellow ethicalhacker members at Black hat!
April 29, 2013 at 8:22 am #52181
May 8, 2013 at 12:41 am #52182TribanParticipant
Just listened to that on the way home today, interesting stuff.
May 9, 2013 at 8:34 am #52183
More insight into the course:
- You must be logged in to reply to this topic.