GNUCITIZEN Pdp Owasp Usa 2007

Loading...

Flash Player 9 (or above) is needed to view presentations.
We have detected that you do not have it on your computer. To install it, go here.

0 comments

Post a comment

    Post a comment
    Embed Video
    Edit your comment Cancel

    Favorites, Groups & Events

    GNUCITIZEN Pdp Owasp Usa 2007 - Presentation Transcript

    1. For my next trick... hacking Web2.0 ( lite )
        • Petko D. Petkov (pdp)
        • GNUCITIZEN
        • http://www.gnucitizen.org
    2. powered BY http://www.gnucitizen.org
    3. ...before we START
      • Feel free to ask questions!
      • Do ask questions!
      • Have fun!
    4. what is WEB2.0?
    5. ...
      • Marketing buzzword
      • Invented by O'Reilly Media in 2003
      • Wikis, Blogs, AJAX, Social Networks, Collaboration
      • APIs, SOA (Service Oriented Architecture)
      • Data in the Cloud
      • Applications on Demand
    6. why web2.0 HACKING?
    7. ...
      • Data Management
      • Information Leaks
      • Live Profiling
      • Information Spamming
      • Service Abuse
      • Autonomous Agents
      • Distribution
      • Attack Infrastructures
    8. the PAPER
      • 5 fictional stories with technology that is real
      • Learn by example
      • KISS (Keep it Simple Stupid)
      • Problems with no solutions
        • I was told that I need to come up with some solutions, otherwise I cannot present at OWASP.
    9. the STORIES
      • MPack2.0
        • Attack Infrastructures
      • Wormoholic
        • Autonomous Agents
      • Bookmarks Rider
        • Distribution
      • RSS Kingpin
        • Information Spamming
      • Revealing the hidden Web
        • Service Abuse
    10. know your ROOTS
    11. ... what's MPACK?
    12. ... what would it be in the web2.0 WORLD? hint: Google Mashup Editor
    13. ... who is SAMY?
    14. ... what's a covert CHANNEL?
    15. ... ...but in the web2.0 WORLD?
    16. ... who's the mechanical TURK?
    17. ... ...to MALWARE? hint: Social Bookmarking
    18. ... can web2.0 malware BROADCAST?
    19. ... ...MD5(DOMAIN + TIME)
    20. ... where are my SCHEDULERS?
    21. ... where are my ACTUATORS?
    22. ... ...data in the CLOUD... (the malicious one)
    23. ... ...applications on DEMAND... (the malicious ones)
    24. ... what's state and what's PERSISTENCE?
    25. ... riding social bookmarks is FUN!
    26. ... ...maybe make some money TOO!
    27. ... to splog or not to splog. This is the QUESTION!
    28. ... call me the rss KINGPIN!
    29. ... service abuse and the hidden WEB
    30. know your ROOTS
    31. ...more
      • Profiling targets by watching their Web activities
      • Snoop onto targets
      • GEO Position Mobile phones
      • GEO Position individuals
      • More service abuse
      • More vulnerabilities
      • More Insecurities
    32. ... solutions and recommendations?
    33. thank YOU http://www.gnucitizen.org

    + guest20ab09guest20ab09, 2 years ago

    custom

    900 views, 0 favs, 0 embeds more stats

    GNUCITIZEN presentation on hacking with Web2.0 serv more

    More Info

    © All Rights Reserved

    Go to text version
    • Total Views 900
      • 900 on SlideShare
      • 0 from embeds
    • Comments 0
    • Favorites 0
    • Downloads 16
    Most viewed embeds

    more

    All embeds

    less

    Flagged as inappropriate Flag as inappropriate
    Flag as innappropriate

    Select your reason for flagging this presentation as inappropriate. If needed, use the feedback form to let us know more details.

    Cancel

    Categories