SlideShare a Scribd company logo
1 of 61
Download to read offline
HACK IN THE BOX
  DUBAI 2008
pdp
information security researcher, hacker, founder of GNUCITIZEN
Cutting-edge Think Tank
ABOUT GNUCITIZEN
 Think tank
     Research
     Training
 Ethical Hacker Outfit
     Responsible disclosure
     We have nothing to hide
 Tiger Team
     The only active Tiger Team in UK.
     Proud to have some of the best pros in our team.
OTHERS
 Hakiri
     Hacker Lifestyle
 Spin Hunters
     Social Hacking Research House
CLIENT-SIDE SECURITY
Overview of various Client-Side Hacking Tricks and Techniques
Client Side Security - Hack in The Box Dubai 2008
Client Side Security - Hack in The Box Dubai 2008
Client Side Security - Hack in The Box Dubai 2008
Client Side Security - Hack in The Box Dubai 2008
Client Side Security - Hack in The Box Dubai 2008
Client Side Security - Hack in The Box Dubai 2008
Client Side Security - Hack in The Box Dubai 2008
Client Side Security - Hack in The Box Dubai 2008
Client Side Security - Hack in The Box Dubai 2008
Client Side Security - Hack in The Box Dubai 2008
Client Side Security - Hack in The Box Dubai 2008
Client Side Security - Hack in The Box Dubai 2008
Client Side Security - Hack in The Box Dubai 2008
Client Side Security - Hack in The Box Dubai 2008
Client Side Security - Hack in The Box Dubai 2008
Client Side Security - Hack in The Box Dubai 2008
Client Side Security - Hack in The Box Dubai 2008
Client Side Security - Hack in The Box Dubai 2008
Client Side Security - Hack in The Box Dubai 2008
Client Side Security - Hack in The Box Dubai 2008
Client Side Security - Hack in The Box Dubai 2008
Client Side Security - Hack in The Box Dubai 2008
Client Side Security - Hack in The Box Dubai 2008
Client Side Security - Hack in The Box Dubai 2008
Client Side Security - Hack in The Box Dubai 2008
Client Side Security - Hack in The Box Dubai 2008
Client Side Security - Hack in The Box Dubai 2008
Client Side Security - Hack in The Box Dubai 2008
Client Side Security - Hack in The Box Dubai 2008
Client Side Security - Hack in The Box Dubai 2008
Client Side Security - Hack in The Box Dubai 2008
Client Side Security - Hack in The Box Dubai 2008
Client Side Security - Hack in The Box Dubai 2008
Client Side Security - Hack in The Box Dubai 2008
Client Side Security - Hack in The Box Dubai 2008
Client Side Security - Hack in The Box Dubai 2008
Client Side Security - Hack in The Box Dubai 2008
Client Side Security - Hack in The Box Dubai 2008
Client Side Security - Hack in The Box Dubai 2008
Client Side Security - Hack in The Box Dubai 2008
Client Side Security - Hack in The Box Dubai 2008
Client Side Security - Hack in The Box Dubai 2008
Client Side Security - Hack in The Box Dubai 2008
Client Side Security - Hack in The Box Dubai 2008
Client Side Security - Hack in The Box Dubai 2008
Client Side Security - Hack in The Box Dubai 2008
Client Side Security - Hack in The Box Dubai 2008
Client Side Security - Hack in The Box Dubai 2008
Client Side Security - Hack in The Box Dubai 2008
Client Side Security - Hack in The Box Dubai 2008
Client Side Security - Hack in The Box Dubai 2008
Client Side Security - Hack in The Box Dubai 2008
Client Side Security - Hack in The Box Dubai 2008
Client Side Security - Hack in The Box Dubai 2008
Client Side Security - Hack in The Box Dubai 2008

More Related Content

Similar to Client Side Security - Hack in The Box Dubai 2008

Design thinking in startups slideshare version
Design thinking in startups slideshare versionDesign thinking in startups slideshare version
Design thinking in startups slideshare versionesegalico
 
Entrepreneur! london 2012 slideshare
Entrepreneur! london 2012 slideshareEntrepreneur! london 2012 slideshare
Entrepreneur! london 2012 slideshareErik Scarcia
 
The mardarch showcase 2013 2
The mardarch showcase 2013 2The mardarch showcase 2013 2
The mardarch showcase 2013 2ronakbk
 
UX Australia 2015 Redux
UX Australia 2015 ReduxUX Australia 2015 Redux
UX Australia 2015 ReduxAnthony Clark
 
The Hardest Thing To Get Right (GeekWire Startup Day 2015)
The Hardest Thing To Get Right (GeekWire Startup Day 2015)The Hardest Thing To Get Right (GeekWire Startup Day 2015)
The Hardest Thing To Get Right (GeekWire Startup Day 2015)Jordan Ritter
 
Design thinking for geeks
Design thinking for geeksDesign thinking for geeks
Design thinking for geeksNina Khosla
 
Understanding Content: The Stuff We Design For
Understanding Content: The Stuff We Design ForUnderstanding Content: The Stuff We Design For
Understanding Content: The Stuff We Design ForKaren McGrane
 
Prototyping approach and platforms nov. 2020
Prototyping approach and platforms nov. 2020Prototyping approach and platforms nov. 2020
Prototyping approach and platforms nov. 2020Filippo Scorza
 
Innovation Diagnostic @daniel_egger
Innovation Diagnostic @daniel_eggerInnovation Diagnostic @daniel_egger
Innovation Diagnostic @daniel_eggerDaniel Egger
 
Innovation Myth Buster at Target's Innovation Network Nov 2009
Innovation Myth Buster at Target's Innovation Network Nov 2009Innovation Myth Buster at Target's Innovation Network Nov 2009
Innovation Myth Buster at Target's Innovation Network Nov 2009Mindful Innovation, Inc.
 
Innovation Myth Buster at Target Innovaiton Network Nov 2009
Innovation Myth Buster at Target Innovaiton Network Nov 2009Innovation Myth Buster at Target Innovaiton Network Nov 2009
Innovation Myth Buster at Target Innovaiton Network Nov 2009guestb97369f
 
Week 3: Handout dean designed to scale - a framework - 040117
Week 3: Handout dean designed to scale - a framework - 040117Week 3: Handout dean designed to scale - a framework - 040117
Week 3: Handout dean designed to scale - a framework - 040117Talou Diallo
 
Week 04_Designed to scale handout
Week 04_Designed to scale handoutWeek 04_Designed to scale handout
Week 04_Designed to scale handoutTokunbo Anifalaje
 
ALF Innovation and Testing Adam Knight
ALF Innovation and Testing Adam KnightALF Innovation and Testing Adam Knight
ALF Innovation and Testing Adam KnightAdam Knight
 
Upgrade Your Offer! How to Sell Business Value
Upgrade Your Offer! How to Sell Business ValueUpgrade Your Offer! How to Sell Business Value
Upgrade Your Offer! How to Sell Business ValueJakob Persson
 
Using Design Thinking in Innovation and How to Apply it to Your Career
Using Design Thinking in Innovation and How to Apply it to Your CareerUsing Design Thinking in Innovation and How to Apply it to Your Career
Using Design Thinking in Innovation and How to Apply it to Your CareerCraig Damlo
 

Similar to Client Side Security - Hack in The Box Dubai 2008 (20)

Design thinking in startups slideshare version
Design thinking in startups slideshare versionDesign thinking in startups slideshare version
Design thinking in startups slideshare version
 
Entrepreneur! london 2012 slideshare
Entrepreneur! london 2012 slideshareEntrepreneur! london 2012 slideshare
Entrepreneur! london 2012 slideshare
 
The mardarch showcase 2013 2
The mardarch showcase 2013 2The mardarch showcase 2013 2
The mardarch showcase 2013 2
 
UX Australia 2015 Redux
UX Australia 2015 ReduxUX Australia 2015 Redux
UX Australia 2015 Redux
 
The Hardest Thing To Get Right (GeekWire Startup Day 2015)
The Hardest Thing To Get Right (GeekWire Startup Day 2015)The Hardest Thing To Get Right (GeekWire Startup Day 2015)
The Hardest Thing To Get Right (GeekWire Startup Day 2015)
 
Hcpra 2013 think like a publicist, act like a journalist
Hcpra 2013   think like a publicist, act like a journalistHcpra 2013   think like a publicist, act like a journalist
Hcpra 2013 think like a publicist, act like a journalist
 
Design thinking for geeks
Design thinking for geeksDesign thinking for geeks
Design thinking for geeks
 
Understanding Content: The Stuff We Design For
Understanding Content: The Stuff We Design ForUnderstanding Content: The Stuff We Design For
Understanding Content: The Stuff We Design For
 
Creativity & innovation
Creativity & innovationCreativity & innovation
Creativity & innovation
 
HR Futures Conference Feb09
HR Futures Conference Feb09HR Futures Conference Feb09
HR Futures Conference Feb09
 
Prototyping approach and platforms nov. 2020
Prototyping approach and platforms nov. 2020Prototyping approach and platforms nov. 2020
Prototyping approach and platforms nov. 2020
 
Innovation Diagnostic @daniel_egger
Innovation Diagnostic @daniel_eggerInnovation Diagnostic @daniel_egger
Innovation Diagnostic @daniel_egger
 
The 7 Secrets of Socially Successful Businesses
The 7 Secrets of Socially Successful BusinessesThe 7 Secrets of Socially Successful Businesses
The 7 Secrets of Socially Successful Businesses
 
Innovation Myth Buster at Target's Innovation Network Nov 2009
Innovation Myth Buster at Target's Innovation Network Nov 2009Innovation Myth Buster at Target's Innovation Network Nov 2009
Innovation Myth Buster at Target's Innovation Network Nov 2009
 
Innovation Myth Buster at Target Innovaiton Network Nov 2009
Innovation Myth Buster at Target Innovaiton Network Nov 2009Innovation Myth Buster at Target Innovaiton Network Nov 2009
Innovation Myth Buster at Target Innovaiton Network Nov 2009
 
Week 3: Handout dean designed to scale - a framework - 040117
Week 3: Handout dean designed to scale - a framework - 040117Week 3: Handout dean designed to scale - a framework - 040117
Week 3: Handout dean designed to scale - a framework - 040117
 
Week 04_Designed to scale handout
Week 04_Designed to scale handoutWeek 04_Designed to scale handout
Week 04_Designed to scale handout
 
ALF Innovation and Testing Adam Knight
ALF Innovation and Testing Adam KnightALF Innovation and Testing Adam Knight
ALF Innovation and Testing Adam Knight
 
Upgrade Your Offer! How to Sell Business Value
Upgrade Your Offer! How to Sell Business ValueUpgrade Your Offer! How to Sell Business Value
Upgrade Your Offer! How to Sell Business Value
 
Using Design Thinking in Innovation and How to Apply it to Your Career
Using Design Thinking in Innovation and How to Apply it to Your CareerUsing Design Thinking in Innovation and How to Apply it to Your Career
Using Design Thinking in Innovation and How to Apply it to Your Career
 

Recently uploaded

Commit 2024 - Secret Management made easy
Commit 2024 - Secret Management made easyCommit 2024 - Secret Management made easy
Commit 2024 - Secret Management made easyAlfredo García Lavilla
 
Take control of your SAP testing with UiPath Test Suite
Take control of your SAP testing with UiPath Test SuiteTake control of your SAP testing with UiPath Test Suite
Take control of your SAP testing with UiPath Test SuiteDianaGray10
 
Search Engine Optimization SEO PDF for 2024.pdf
Search Engine Optimization SEO PDF for 2024.pdfSearch Engine Optimization SEO PDF for 2024.pdf
Search Engine Optimization SEO PDF for 2024.pdfRankYa
 
SAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptxSAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptxNavinnSomaal
 
Unleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding ClubUnleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding ClubKalema Edgar
 
From Family Reminiscence to Scholarly Archive .
From Family Reminiscence to Scholarly Archive .From Family Reminiscence to Scholarly Archive .
From Family Reminiscence to Scholarly Archive .Alan Dix
 
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdf
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdfHyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdf
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdfPrecisely
 
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek SchlawackFwdays
 
Dev Dives: Streamline document processing with UiPath Studio Web
Dev Dives: Streamline document processing with UiPath Studio WebDev Dives: Streamline document processing with UiPath Studio Web
Dev Dives: Streamline document processing with UiPath Studio WebUiPathCommunity
 
Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024Scott Keck-Warren
 
Artificial intelligence in cctv survelliance.pptx
Artificial intelligence in cctv survelliance.pptxArtificial intelligence in cctv survelliance.pptx
Artificial intelligence in cctv survelliance.pptxhariprasad279825
 
How to write a Business Continuity Plan
How to write a Business Continuity PlanHow to write a Business Continuity Plan
How to write a Business Continuity PlanDatabarracks
 
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks..."LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...Fwdays
 
Developer Data Modeling Mistakes: From Postgres to NoSQL
Developer Data Modeling Mistakes: From Postgres to NoSQLDeveloper Data Modeling Mistakes: From Postgres to NoSQL
Developer Data Modeling Mistakes: From Postgres to NoSQLScyllaDB
 
DevoxxFR 2024 Reproducible Builds with Apache Maven
DevoxxFR 2024 Reproducible Builds with Apache MavenDevoxxFR 2024 Reproducible Builds with Apache Maven
DevoxxFR 2024 Reproducible Builds with Apache MavenHervé Boutemy
 
Scanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL CertsScanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL CertsRizwan Syed
 
TrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data PrivacyTrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data PrivacyTrustArc
 
Story boards and shot lists for my a level piece
Story boards and shot lists for my a level pieceStory boards and shot lists for my a level piece
Story boards and shot lists for my a level piececharlottematthew16
 
Vertex AI Gemini Prompt Engineering Tips
Vertex AI Gemini Prompt Engineering TipsVertex AI Gemini Prompt Engineering Tips
Vertex AI Gemini Prompt Engineering TipsMiki Katsuragi
 

Recently uploaded (20)

Commit 2024 - Secret Management made easy
Commit 2024 - Secret Management made easyCommit 2024 - Secret Management made easy
Commit 2024 - Secret Management made easy
 
Take control of your SAP testing with UiPath Test Suite
Take control of your SAP testing with UiPath Test SuiteTake control of your SAP testing with UiPath Test Suite
Take control of your SAP testing with UiPath Test Suite
 
Search Engine Optimization SEO PDF for 2024.pdf
Search Engine Optimization SEO PDF for 2024.pdfSearch Engine Optimization SEO PDF for 2024.pdf
Search Engine Optimization SEO PDF for 2024.pdf
 
SAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptxSAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptx
 
Unleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding ClubUnleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding Club
 
From Family Reminiscence to Scholarly Archive .
From Family Reminiscence to Scholarly Archive .From Family Reminiscence to Scholarly Archive .
From Family Reminiscence to Scholarly Archive .
 
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdf
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdfHyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdf
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdf
 
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
 
Dev Dives: Streamline document processing with UiPath Studio Web
Dev Dives: Streamline document processing with UiPath Studio WebDev Dives: Streamline document processing with UiPath Studio Web
Dev Dives: Streamline document processing with UiPath Studio Web
 
Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024
 
Artificial intelligence in cctv survelliance.pptx
Artificial intelligence in cctv survelliance.pptxArtificial intelligence in cctv survelliance.pptx
Artificial intelligence in cctv survelliance.pptx
 
How to write a Business Continuity Plan
How to write a Business Continuity PlanHow to write a Business Continuity Plan
How to write a Business Continuity Plan
 
DMCC Future of Trade Web3 - Special Edition
DMCC Future of Trade Web3 - Special EditionDMCC Future of Trade Web3 - Special Edition
DMCC Future of Trade Web3 - Special Edition
 
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks..."LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
 
Developer Data Modeling Mistakes: From Postgres to NoSQL
Developer Data Modeling Mistakes: From Postgres to NoSQLDeveloper Data Modeling Mistakes: From Postgres to NoSQL
Developer Data Modeling Mistakes: From Postgres to NoSQL
 
DevoxxFR 2024 Reproducible Builds with Apache Maven
DevoxxFR 2024 Reproducible Builds with Apache MavenDevoxxFR 2024 Reproducible Builds with Apache Maven
DevoxxFR 2024 Reproducible Builds with Apache Maven
 
Scanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL CertsScanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL Certs
 
TrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data PrivacyTrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data Privacy
 
Story boards and shot lists for my a level piece
Story boards and shot lists for my a level pieceStory boards and shot lists for my a level piece
Story boards and shot lists for my a level piece
 
Vertex AI Gemini Prompt Engineering Tips
Vertex AI Gemini Prompt Engineering TipsVertex AI Gemini Prompt Engineering Tips
Vertex AI Gemini Prompt Engineering Tips
 

Client Side Security - Hack in The Box Dubai 2008