So, what do these vulnerabilities mean? - Part 1

Learn about Security for code and servers. Learn how to secure your site and your code. Learn about hacking prevention, finding and identifying exploits, and recognising vulnerabilities. Plus, Weekly Security tips and Tutorials.
Forum rules
Post questions related to security, analyse and learn about vulnerabilities and exploits within code to protect yourself against hackers.

So, what do these vulnerabilities mean? - Part 1

Postby Techie-Micheal » 05 Oct 2009, 23:25

Watch via Vimeo: http://www.vimeo.com/6952783

Download m4v video: Webapp Breakage - Part 1

The point of this hopefully series is to show why these vulnerabilities are bad. It's great that people have posted in here to look at code, explain why the code is vulnerable, etc., but so what if the code is vulnerable? This first part covers XSS.
Techie-Micheal    
STG Development
STG Development
 
Posts: 57
Joined: 26 Oct 2007, 21:35
Gender: Male
phpBB Knowledge: 10


Re: So, what do these vulnerabilities mean? - Part 1

Postby SamT » 06 Oct 2009, 00:29

The audio cuts off at 18:18 for me... D:

Anyway, it has a lot of useful information.
http://www.websyntax.net - Proudly powered by phpBB.
User avatar
SamT    
phpBB Team Member
phpBB Team Member
 
Posts: 33
Joined: 27 Jan 2009, 01:42
Location: Sacramental, CA
Favorite Team: SF 49ers
Gender: Male
phpBB Knowledge: 9

Re: So, what do these vulnerabilities mean? - Part 1

Postby Techie-Micheal » 06 Oct 2009, 01:41

Fixed the audio and reuploaded. :)
Techie-Micheal    
STG Development
STG Development
 
Posts: 57
Joined: 26 Oct 2007, 21:35
Gender: Male
phpBB Knowledge: 10

Re: So, what do these vulnerabilities mean? - Part 1

Postby Techie-Micheal » 06 Oct 2009, 16:50

Wow, was it that bad? :P Seriously, if you guys don't like it, I won't waste your time by making more. :)
Techie-Micheal    
STG Development
STG Development
 
Posts: 57
Joined: 26 Oct 2007, 21:35
Gender: Male
phpBB Knowledge: 10

Re: So, what do these vulnerabilities mean? - Part 1

Postby Highway of Life » 06 Oct 2009, 17:15

I watched the entire thing, very VERY informative. I learned quite a lot.
Although if I may make a suggestion... I think for many people, they'd rather watch this video on a video site (such as YouTube or Vimeo) rather than downloading it.
Additionally, while the information was good, it was really slow-paced. If I may make a suggestion, see if you can quicken the pace either in real-time or through editing of the video. :)

Other than that, I really liked it and can't wait to see more. :)
Two thumbs up. :good: :good:
Watch out! I might do a code wheelie!

User avatar
Highway of Life    
STG Jedi Master
STG Jedi Master
 
Posts: 10424
Joined: 08 May 2006, 05:23
Location: Beware of Programmers carrying screwdrivers
Gender: Male
phpBB Knowledge: 10

Re: So, what do these vulnerabilities mean? - Part 1

Postby Techie-Micheal » 06 Oct 2009, 17:41

Highway of Life wrote:I watched the entire thing, very VERY informative. I learned quite a lot.
Although if I may make a suggestion... I think for many people, they'd rather watch this video on a video site (such as YouTube or Vimeo) rather than downloading it.
Can do. I wasn't quite sure how well it'd be received, so I didn't want to waste any more time if people didn't like it/find it useful. I will do that for the next one. :)

Additionally, while the information was good, it was really slow-paced. If I may make a suggestion, see if you can quicken the pace either in real-time or through editing of the video. :)
Yeah, I was doing the voiceover while doing the video, so that slowed things down a bit and made editing a bit more difficult. Lesson learned.

Other than that, I really liked it and can't wait to see more. :)
Two thumbs up. :good: :good:
I've got more planned, just a matter of when I get time/if I can find others to help me.
Techie-Micheal    
STG Development
STG Development
 
Posts: 57
Joined: 26 Oct 2007, 21:35
Gender: Male
phpBB Knowledge: 10

Re: So, what do these vulnerabilities mean? - Part 1

Postby Erik Frèrejean » 07 Oct 2009, 05:01

Downloading it atm, now only have to find/make time to actually watch it :scratch:

Edit: Just made time and OMG :shock:, I knew XSS was bad but didn't know you can do this kinda funky stuff with it. Great vid Michael :thumbsup:
Highway of Life wrote:Other than that, I really liked it and can't wait to see more. :)
Two thumbs up. :good: :good:

Quoted for agreement
Last edited by Erik Frèrejean on 07 Oct 2009, 06:21, edited 1 time in total.
Reason: edit
Image Proud member of the phpBB support team
Image STG Support team member | Image STG Moderator team member
Image
User avatar
Erik Frèrejean    
phpBB Team Member
phpBB Team Member
 
Posts: 1021
Joined: 03 Dec 2007, 00:49
Location: USERS_TABLE
Favorite Team: phpBB teams
Gender: Male
phpBB Knowledge: 9

Re: So, what do these vulnerabilities mean? - Part 1

Postby cherokee red » 07 Oct 2009, 07:11

Just downloaded and watched there - very informative I must say, I also had no idea of the full dangers. Thanks for taking time to do this Michael, eager to see more now :)
// 6 String Romance Music // 6 String Romance // Myspace // MODs Development //
Are you a musician in the Glasgow area interested in acoustic events? The ArtBox
User avatar
cherokee red    
Supporter
Supporter
 
Posts: 99
Joined: 04 Apr 2008, 12:02
Location: Airdrie, UK
Favorite Team: Airdrie United
Gender: Male
phpBB Knowledge: 8

Re: So, what do these vulnerabilities mean? - Part 1

Postby Obsidian » 07 Oct 2009, 07:47

You really should upload this to a online video site. :P
- I will not die, I'll wait here for you... -
User avatar
Obsidian    
Supporter
Supporter
 
Posts: 2049
Joined: 04 Mar 2008, 23:35
Gender: Male
phpBB Knowledge: 8

Re: So, what do these vulnerabilities mean? - Part 1

Postby Highway of Life » 07 Oct 2009, 13:56

Obsidian wrote:You really should upload this to a online video site. :P

Ditto Ditto Ditto Ditto Ditto Ditto Ditto Ditto Ditto Ditto!
Watch out! I might do a code wheelie!

User avatar
Highway of Life    
STG Jedi Master
STG Jedi Master
 
Posts: 10424
Joined: 08 May 2006, 05:23
Location: Beware of Programmers carrying screwdrivers
Gender: Male
phpBB Knowledge: 10

Next

Return to Security Class

Who is online

Users browsing this forum: ccBot [Bot] and 0 guests