Dec 9 2009

Secure Programming and Common Errors PART II

Hi to all my readers.

Today I will present the second part of my security seminars at University of Bologna, Italy.

Here the outline:

  • Discuss other important attack vectors, not limited to Web Applications
  • Practical screen-casts that show how attackers exploit common flows
  • Understand the impact of these threats on your privacy, data and identity

You can find the slides here below:

The ScreenCasts can be watched at the following links on Vimeo:
– EsseDi path traversal for fun and profit: http://vimeo.com/8072462
– Unescaped numeric injection in www.dm.unibo.it: http://vimeo.com/8072698
– Konakart 2.2.6.0 stored XSS explitation with BeEF: http://vimeo.com/8072425
– WMSmonitor: reflected XSS exploitation using BeEF: http://vimeo.com/8072497
– Appendix: Sniffing SSL/TLS Connections Through Fake Certificate Injection: http://vimeo.com/8072385