So, what do these vulnerabilities mean? - Part 1

Learn about Security for code and servers. Learn how to secure your site and your code. Learn about hacking prevention, finding and identifying exploits, and recognising vulnerabilities. Plus, Weekly Security tips and Tutorials.
Forum rules
Post questions related to security, analyse and learn about vulnerabilities and exploits within code to protect yourself against hackers.

Re: So, what do these vulnerabilities mean? - Part 1

Postby Techie-Micheal » 07 Oct 2009, 16:55

Techie-Micheal    
STG Development
STG Development
 
Posts: 63
Joined: 26 Oct 2007, 21:35
Gender: Male
phpBB Knowledge: 10




phpBB Academy at StarTrekGuide
Support STG
Using PayPal Donate

Re: So, what do these vulnerabilities mean? - Part 1

Postby Highway of Life » 07 Oct 2009, 17:36

Wonderful. :D
- First post edited.
Watch out! I might do a code wheelie!

User avatar
Highway of Life    
STG Jedi Master
STG Jedi Master
 
Posts: 10458
Joined: 08 May 2006, 05:23
Location: Beware of Programmers carrying screwdrivers
Gender: Male
phpBB Knowledge: 10

Re: So, what do these vulnerabilities mean? - Part 1

Postby comkid » 14 Oct 2009, 23:26

Does this show you how to fix those vulnerabilities pointed out?

Even if it doesn't I'm still watching it :D
comkid
MOD Author
MOD Author
 
Posts: 105
Joined: 07 Jun 2009, 06:19
Gender: Male
phpBB Knowledge: 6

Re: So, what do these vulnerabilities mean? - Part 1

Postby Obsidian » 14 Oct 2009, 23:35

No, it does not. I believe that may be covered in later videos, but best to know from Techie-Micheal himself. :)
うるさいうるさいうるさい!

StopForumSpam Spam Reporting Database
Giving xrumer and friends a great big "screw you" since 2007.
User avatar
Obsidian    
Supporter
Supporter
 
Posts: 2250
Joined: 04 Mar 2008, 23:35
Gender: Male
phpBB Knowledge: 10

Re: So, what do these vulnerabilities mean? - Part 1

Postby Highway of Life » 15 Oct 2009, 00:40

comkid wrote:Does this show you how to fix those vulnerabilities pointed out?

Even if it doesn't I'm still watching it :D

The first step is always becoming aware of these vulnerabilities. Once you are aware of them and how they work, you can better diagnose what you should be doing to prevent such vulnerabilities.
Watch out! I might do a code wheelie!

User avatar
Highway of Life    
STG Jedi Master
STG Jedi Master
 
Posts: 10458
Joined: 08 May 2006, 05:23
Location: Beware of Programmers carrying screwdrivers
Gender: Male
phpBB Knowledge: 10

Re: So, what do these vulnerabilities mean? - Part 1

Postby wired076 » 15 Oct 2009, 00:51

I have just watched this video and it was very interesting and informative.

I would like to see some more videos of this nature not just of showing exploits but also how to fix them and how to protect yourself,etc.

I think that this is something that should be covered more.

Thanks Techie-Micheal keep up the good work!
I.T. Construct
STG Supporter
Please contact me via email/im for help at reasonable prices.
USA Based Web hosting
email: admin@itconstruct.com.au
- Visit http://www.itconstruct.com.au
wired076    
Supporter
Supporter
 
Posts: 494
Joined: 03 Feb 2009, 16:51
Location: Australia
Gender: Male
phpBB Knowledge: 5

Re: So, what do these vulnerabilities mean? - Part 1

Postby Obsidian » 15 Oct 2009, 09:03

wired076 wrote:I have just watched this video and it was very interesting and informative.

I would like to see some more videos of this nature not just of showing exploits but also how to fix them and how to protect yourself,etc.

I think that this is something that should be covered more.

Thanks Techie-Micheal keep up the good work!


I think he was going for the shock-and-awe effect with this video, to make developers aware of the implications an XSS vulnerability may have. Before you can get people to listen to you, you need to have their attention -- this certainly worked for that purpose.

I'm really looking forward to more videos though. Bring it on, TM!
うるさいうるさいうるさい!

StopForumSpam Spam Reporting Database
Giving xrumer and friends a great big "screw you" since 2007.
User avatar
Obsidian    
Supporter
Supporter
 
Posts: 2250
Joined: 04 Mar 2008, 23:35
Gender: Male
phpBB Knowledge: 10

Re: So, what do these vulnerabilities mean? - Part 1

Postby Techie-Micheal » 15 Oct 2009, 23:16

Highway of Life wrote:
comkid wrote:Does this show you how to fix those vulnerabilities pointed out?

Even if it doesn't I'm still watching it :D

The first step is always becoming aware of these vulnerabilities. Once you are aware of them and how they work, you can better diagnose what you should be doing to prevent such vulnerabilities.
Exactly. :)

Obsidian wrote:
wired076 wrote:I have just watched this video and it was very interesting and informative.

I would like to see some more videos of this nature not just of showing exploits but also how to fix them and how to protect yourself,etc.

I think that this is something that should be covered more.

Thanks Techie-Micheal keep up the good work!


I think he was going for the shock-and-awe effect with this video, to make developers aware of the implications an XSS vulnerability may have. Before you can get people to listen to you, you need to have their attention -- this certainly worked for that purpose.

I'm really looking forward to more videos though. Bring it on, TM!
Exactly what I was after. :) Too often I've either reported or seen reports to developers of XSS or SQL injection or others like weak PRNG, and they just shrug it off, like it isn't a big deal. Well, it is. The next video will hopefully be SQL injection and I've got some surprises in mind with that. Here's a little teaser to whet your appetite: I can go from SQL injection to running operating system commands on the server. I'll show you how that works once I get settled in and get internet access at my new apartment. Once we understand the severity of these vulnerabilities, we can start formulating our own plan of attack to secure our applications.
Techie-Micheal    
STG Development
STG Development
 
Posts: 63
Joined: 26 Oct 2007, 21:35
Gender: Male
phpBB Knowledge: 10

Re: So, what do these vulnerabilities mean? - Part 1

Postby comkid » 16 Oct 2009, 02:09

Great, I want to see what the exploit is...
comkid
MOD Author
MOD Author
 
Posts: 105
Joined: 07 Jun 2009, 06:19
Gender: Male
phpBB Knowledge: 6

Re: So, what do these vulnerabilities mean? - Part 1

Postby Obsidian » 16 Oct 2009, 19:28

Techie-Micheal wrote:Exactly what I was after. :) Too often I've either reported or seen reports to developers of XSS or SQL injection or others like weak PRNG, and they just shrug it off, like it isn't a big deal. Well, it is. The next video will hopefully be SQL injection and I've got some surprises in mind with that. Here's a little teaser to whet your appetite: I can go from SQL injection to running operating system commands on the server. I'll show you how that works once I get settled in and get internet access at my new apartment. Once we understand the severity of these vulnerabilities, we can start formulating our own plan of attack to secure our applications.


Oh yay! Another interesting video to watch. :yahoo:

Just be sure to upload the next one too, if you please. :)
うるさいうるさいうるさい!

StopForumSpam Spam Reporting Database
Giving xrumer and friends a great big "screw you" since 2007.
User avatar
Obsidian    
Supporter
Supporter
 
Posts: 2250
Joined: 04 Mar 2008, 23:35
Gender: Male
phpBB Knowledge: 10

PreviousNext

Return to Security Class

Who is online

Users browsing this forum: No registered users and 1 guest