Black Hat USA Registration Black Hat USA Registration Black Hat USA Briefings Black Hat USA Briefings Black Hat USA Training Black Hat USA Training Black Hat USA Schedule Black Hat USA Schedule Black Hat USA Sponsors Black Hat USA Sponsors Black Hat  USA Special Events Black Hat  USA Special Events Black Hat USA Venue Black Hat USA Venue
 
 

On This Page

The Art of Exploiting Injection Flaws

Sumit Siddharth | July 29-30


Regular

$1800

Ends May 31

Late

$2000

Ends July 24

Onsite

$2200

Ends July 30



Overview

OWASP rates injection flaws as the most critical vulnerability within the Top 10 most Critical Web Application Security Risks under the OWASP Top 10 project. http://www.owasp.org/index.php/Top_10_2010-A1

Watch Sid talk about the upcoming course here: http://www.ustream.tv/recorded/31958833

This hands-on session will only focus on the injection flaws and the attendees will get an in-depth understanding of the flaws arising from this vulnerability. The topics covered in the class are:

During the 2 days course, the attendees will have access to a number of challenges for each flaw and they will learn a variety of exploitation techniques used by the attackers in the wild. Identify, extract, escalate, execute; we have got it all covered. The following are the objectives of the course:

  1. Understand the problem of Injection Flaws
  2. Learn a variety of advanced exploitation techniques which hackers use.
  3. learn how to fix these problems?


What Students Will Be Provided


Who should attend


What to Expect


What Students Should Bring

Students must bring their own laptop with Windows Operating System installed (either natively or running in a VM). Further, students must have administrative access to perform tasks like install software, disable antivirus etc. Devices which don't have ethernet connection (e.g. macbook Air, tablets etc) are not supported. A prior knowledge of Database systems and SQL language will be an added advantage but it's not a strict requirement.


Trainers

Sumit "sid" Siddharth works as a Head of Penetration testing for 7Safe Limited in the UK. He specializes in the application and database security and has more than 8 years of experience in Penetration Testing. Sid has authored a number of whitepapers and tools. He has been a Speaker/Trainer at many security conferences including Black Hat, DEF CON, OWASP Appsec, HITB etc. He also runs the popular IT security blog: www.notsosecure.com. Sid is also a co-author of the book SQL Injection: Attacks and Defence (2nd edition).