BetterEditor.org - online resources for editors and writers

   
 
Sponsored Links
 

 

 

Dictionaries

Online
Science
Computing
Thesaurus
Etymology
Acronyms
Rhyming
Multilingual
Medical
Biographical
Slang

 
Style Guides
General
Grammar
Citation
Spelling
 
Reference

Bibliographies
Encyclopedias
Science Libraries
Units of Measurement
Quotations
Languages
Maps
Time
Geography
Library Directories
Online Catalogs

 
Miscellaneous

Bookstore
Media News
About BetterEditor
Add Your Link
Report Broken Link
Contact

 

BetterEditor.org Media News

BetterEditor.org's Media News charts the latest developments in the world of magazines, books, and Internet publishing with press updates published to this feed as they are released. BetterEditor.org's Media News feed is updated daily.


Monday, July 23, 2007

 

SPI Dynamics Expert Researchers to Demonstrate Hacking Ajax Web Applications and the Latest in Hybrid Web Application Worm Threats at Black Hat USA 2007

SPI Dynamics Expert Researchers to Demonstrate Hacking Ajax Web Applications and the Latest in Hybrid Web Application Worm Threats at Black Hat USA 2007

Company's Security Evangelist, Michael Sutton, Will Take Part in Book Signing for the Release of, "Fuzzing: Brute Force Vulnerability Discovery"

ATLANTA, July 23 /PRNewswire/ -- S.P.I. Dynamics, Inc. (http://www.spidynamics.com/ ), the leading provider of web application security, today announced two of the company's expert researchers will highlight the latest in hacking web applications at the upcoming Black Hat USA 2007 conference at Caesar's Palace in Las Vegas, Nevada, August 1-2. Similar to last year's successful event, this year's Black Hat includes a significant number of talks focused specifically on web application security, underscoring the critical impact aggressively evolving application development technologies such as Ajax are having on today's security industry.

The popularity of Ajax is growing exponentially due to its ability to make web applications much more usable. Unfortunately, far too many people rush into Ajax development without giving proper consideration to the overwhelming possibility of security ramifications that stem from its ability to greatly amplify the same types of common vulnerabilities found in more traditional web applications. Bryan Sullivan, Ajax expert and Senior Security Researcher for SPI Dynamics' SPI Labs research division, will present alongside the Lead SPI Labs Security Researcher and Ajax expert, Billy Hoffman, on Ajax security. The talk titled, "Premature Ajax-ulation" is scheduled during the Black Hat conference on Wednesday, August 1st from 3:15 to 4:30 p.m. PT.

This presentation will demonstrate specific Ajax application design flaws that stem from a disregard for security including improper use of client-side XSLT, use of overly- or underly-granular server-side APIs, and storing secrets (either data or functionality) in client-side code. In addition, this session will demonstrate exploits of these vulnerabilities including: vastly more efficient Blind SQL and Blind XPath injection techniques, detecting and exploiting race conditions, and applying static analysis to deobfuscate client-side JavaScript. The session will also explore when to use and when to avoid the use of Ajax, and how the use of third-party frameworks can actually make matters worse since they hide potential security issues without truly resolving them.

Messrs. Sullivan and Hoffman will also debut a portion of their soon-to- be-released book titled Ajax Security published by Addison-Wesley Professional during Black Hat that will be available to conference attendees in the SPI Dynamics booth (# 9).

Hoffman will co-present another talk at the conference with John Terrill, Executive Vice President and Co-founder of Enterprise Management Technology LLC, focused on the latest in web application hybrid worms. The talk titled, "The Little Hybrid Web Worm that Could" is scheduled for Thursday, August 2nd from 11:15 a.m. to 12:30 p.m. PT. The presentation will discuss the rise in sophisticated web worm attacks over the past year with a look at some of the basic limitations in their methods, including the ability to detect these worms using signatures, making them annoying but ultimately controllable. The presentation will examine the possible evolution of web worms to overcome these limitations, with a description of a hybrid web worm combining both server-side and client side languages to exploit both the web server and the web browser to aid in its propagation across multiple hosts. The presentation will also take a look at how a hybrid web worm could upgrade its infection methods while in the wild by fetching and parsing new web vulnerability information from public security sites, preventing a single silver bullet fix from stopping its propagation, and how web worms could implement polymorphism and source code mutation to evade signature detection systems.

Messrs. Hoffman and Terrill will demo different parts of the worm in isolation to show how its features would function, with a specific look at how the worm could upgrade itself with publicly available vulnerability data, as well as source code mutation. Based on methodology from the JavaScript vulnerability scanner Jikto, Messrs. Hoffman and Terrill will demonstrate DOMinatrix, a JavaScript payload using SQL Injection, to extract information from a web site's database. Finally, the presentation will discuss steps to prevent hybrid web worms from exploiting a web site or its users.

In addition, SPI Dynamics' Security Evangelist, Michael Sutton, will participate in a book signing at Black Hat for the new release of his book titled, Fuzzing: Brute Force Vulnerability Discovery, published by Addison Wesley Professional and co-authored by Pedram Amini and Adam Greene. The signing will take place on Wednesday, August 1st from 3:00 p.m. to 3:15 p.m. PT. For more information on Fuzzing: Brute Force Vulnerability Discovery, please visit http://www.awprofessional.com/bookstore/product.asp?isbn=0321446119&rl=1 .

For more information on SPI Dynamics, please visit http://www.spidynamics.com/ .

About S.P.I. Dynamics, Inc.

SPI Dynamics' comprehensive suite of products and services identify and remediate web application and web services security vulnerabilities throughout the application development lifecycle. These award-winning solutions also enable security professionals, QA testers, and developers to work together to verify compliance with 22 security policies such as SOX, HIPAA and PCI. SPI Dynamics has the most application security testing customers worldwide - over 1,000 clients among Global 2000 enterprises, including four out of five of the world's largest banks and nine out of 10 of the largest banks in the U.S., four out of five of the largest software companies, three out of four of the largest aerospace and defense companies, the four largest accounting firms, the five largest telecommunications companies in the U.S., six out of eight of the largest technology hardware and equipment companies, two out of three of the largest healthcare companies, and over 90 U.S. Federal agencies. The Company is one of the fastest growing in the security industry, ranked 83rd on Deloitte's "Fast 500" list of growing technology companies nationwide and 220th on the Inc. 500. SPI Dynamics has strategic partnerships with Microsoft, IBM, HP and Visa. The Company's R&D team, SPI Labs, is widely recognized as one of the leading authorities on web application security and risk management. For more information, visit www.spidynamics.com or call (866) 774-2700.

Product or service names mentioned herein are the trademarks of their respective owners.

First Call Analyst:
FCMN Contact:


Source: S.P.I. Dynamics, Inc.

CONTACT: Michelle Schafer of Merritt Group, +1-703-390-1525, cell,
+1-703-403-6377, schafer@merrittgrp.com; or Ashley Vandiver of SPI Dynamics,
+1-678-781-4841, cell, +1-404-432-8657, avandiver@spidynamics.com

Web site:

http://www.spidynamics.com/
http://www.awprofessional.com/bookstore/product.asp?isbn=0321446119&rl=1


-------
Profile: Media News


Archives

Jul 9, 2007   Jul 10, 2007   Jul 11, 2007   Jul 12, 2007   Jul 13, 2007   Jul 15, 2007   Jul 16, 2007   Jul 17, 2007   Jul 18, 2007   Jul 19, 2007   Jul 20, 2007   Jul 21, 2007   Jul 22, 2007   Jul 23, 2007   Jul 24, 2007   Jul 25, 2007   Jul 26, 2007   Jul 27, 2007   Jul 29, 2007   Jul 30, 2007   Jul 31, 2007   Aug 1, 2007   Aug 2, 2007   Aug 3, 2007   Aug 6, 2007   Aug 7, 2007   Aug 8, 2007   Aug 9, 2007   Aug 10, 2007   Aug 12, 2007   Aug 13, 2007   Aug 14, 2007   Aug 15, 2007   Aug 16, 2007   Aug 17, 2007   Aug 20, 2007   Aug 21, 2007   Aug 22, 2007   Aug 23, 2007   Aug 24, 2007   Aug 27, 2007   Aug 28, 2007   Aug 29, 2007   Aug 30, 2007   Aug 31, 2007   Sep 3, 2007   Sep 4, 2007   Sep 5, 2007   Sep 6, 2007   Sep 7, 2007   Sep 9, 2007   Sep 10, 2007   Sep 11, 2007   Sep 12, 2007   Sep 13, 2007   Sep 14, 2007   Sep 15, 2007   Sep 16, 2007   Sep 17, 2007   Sep 18, 2007   Sep 19, 2007   Sep 20, 2007   Sep 21, 2007   Sep 23, 2007   Sep 24, 2007   Sep 25, 2007   Sep 26, 2007   Sep 27, 2007   Sep 28, 2007   Oct 1, 2007   Oct 2, 2007   Oct 3, 2007   Oct 4, 2007   Oct 5, 2007   Oct 7, 2007   Oct 8, 2007   Oct 9, 2007   Oct 10, 2007   Oct 11, 2007   Oct 12, 2007   Oct 14, 2007   Oct 15, 2007   Oct 16, 2007   Oct 17, 2007   Oct 18, 2007   Oct 19, 2007   Oct 20, 2007   Oct 21, 2007   Oct 22, 2007   Oct 23, 2007   Oct 24, 2007   Oct 25, 2007   Oct 26, 2007   Oct 28, 2007   Oct 29, 2007   Oct 30, 2007   Oct 31, 2007   Nov 1, 2007   Nov 2, 2007   Nov 3, 2007   Nov 5, 2007   Nov 6, 2007   Nov 7, 2007   Nov 8, 2007   Nov 9, 2007   Nov 10, 2007   Nov 11, 2007   Nov 12, 2007   Nov 13, 2007   Nov 14, 2007   Nov 15, 2007   Nov 16, 2007   Nov 18, 2007   Nov 19, 2007   Nov 20, 2007   Nov 21, 2007   Nov 22, 2007   Nov 25, 2007   Nov 26, 2007   Nov 27, 2007   Nov 28, 2007   Nov 29, 2007   Nov 30, 2007   Dec 2, 2007   Dec 3, 2007   Dec 4, 2007   Dec 5, 2007   Dec 6, 2007   Dec 7, 2007   Dec 10, 2007   Dec 11, 2007   Dec 12, 2007   Dec 13, 2007   Dec 14, 2007   Dec 16, 2007   Dec 17, 2007   Dec 18, 2007   Dec 19, 2007   Dec 20, 2007   Dec 21, 2007   Dec 24, 2007   Dec 25, 2007   Dec 26, 2007   Dec 27, 2007   Dec 28, 2007   Dec 31, 2007   Jan 2, 2008   Jan 3, 2008   Jan 4, 2008   Jan 6, 2008   Jan 7, 2008   Jan 8, 2008   Jan 9, 2008   Jan 10, 2008   Jan 11, 2008   Jan 12, 2008   Jan 13, 2008   Jan 14, 2008   Jan 15, 2008   Jan 16, 2008   Jan 17, 2008   Jan 18, 2008   Jan 20, 2008   Jan 21, 2008   Jan 22, 2008   Jan 23, 2008   Jan 24, 2008   Jan 25, 2008   Jan 27, 2008   Jan 28, 2008   Jan 29, 2008   Jan 30, 2008   Jan 31, 2008   Feb 1, 2008   Feb 2, 2008   Feb 3, 2008   Feb 4, 2008   Feb 5, 2008   Feb 6, 2008   Feb 7, 2008   Feb 8, 2008   Feb 10, 2008   Feb 11, 2008   Feb 12, 2008   Feb 13, 2008   Feb 14, 2008   Feb 15, 2008   Feb 16, 2008   Feb 17, 2008   Feb 18, 2008   Feb 19, 2008   Feb 20, 2008   Feb 21, 2008   Feb 22, 2008   Feb 23, 2008   Feb 24, 2008   Feb 25, 2008   Feb 26, 2008   Feb 27, 2008   Feb 28, 2008   Feb 29, 2008   Mar 1, 2008   Mar 2, 2008   Mar 3, 2008   Mar 4, 2008   Mar 5, 2008   Mar 6, 2008   Mar 7, 2008   Mar 10, 2008   Mar 11, 2008   Mar 12, 2008   Mar 13, 2008   Mar 14, 2008   Mar 15, 2008   Mar 16, 2008   Mar 17, 2008   Mar 18, 2008   Mar 19, 2008   Mar 20, 2008   Mar 21, 2008   Mar 23, 2008   Mar 24, 2008   Mar 25, 2008   Mar 26, 2008   Mar 27, 2008   Mar 28, 2008   Mar 30, 2008   Mar 31, 2008   Apr 1, 2008   Apr 2, 2008   Apr 3, 2008   Apr 4, 2008   Apr 5, 2008   Apr 6, 2008   Apr 7, 2008   Apr 8, 2008   Apr 9, 2008   Apr 10, 2008   Apr 11, 2008   Apr 13, 2008   Apr 14, 2008   Apr 15, 2008   Apr 16, 2008   Apr 17, 2008   Apr 18, 2008   Apr 19, 2008   Apr 20, 2008   Apr 21, 2008   Apr 22, 2008   Apr 23, 2008   Apr 24, 2008   Apr 25, 2008   Apr 27, 2008   Apr 28, 2008   Apr 29, 2008   Apr 30, 2008   May 1, 2008   May 2, 2008   May 4, 2008   May 5, 2008   May 6, 2008   May 7, 2008   May 8, 2008   May 9, 2008   May 10, 2008   May 11, 2008   May 12, 2008   May 13, 2008   May 14, 2008   May 15, 2008   May 16, 2008   May 18, 2008   May 19, 2008   May 20, 2008   May 21, 2008   May 22, 2008   May 23, 2008   May 26, 2008   May 27, 2008   May 28, 2008   May 29, 2008   May 30, 2008   Jun 1, 2008   Jun 2, 2008   Jun 3, 2008   Jun 4, 2008   Jun 5, 2008   Jun 6, 2008   Jun 7, 2008   Jun 8, 2008   Jun 9, 2008   Jun 10, 2008   Jun 11, 2008   Jun 12, 2008   Jun 13, 2008   Jun 14, 2008   Jun 15, 2008   Jun 16, 2008   Jun 17, 2008   Jun 18, 2008   Jun 19, 2008   Jun 20, 2008   Jun 23, 2008   Jun 24, 2008   Jun 25, 2008   Jun 26, 2008   Jun 27, 2008   Jun 29, 2008   Jun 30, 2008   Jul 1, 2008   Jul 2, 2008   Jul 3, 2008   Jul 4, 2008   Jul 6, 2008   Jul 7, 2008   Jul 8, 2008   Jul 9, 2008   Jul 10, 2008   Jul 11, 2008   Jul 13, 2008   Jul 14, 2008   Jul 15, 2008   Jul 16, 2008   Jul 17, 2008   Jul 18, 2008   Jul 20, 2008   Jul 21, 2008   Jul 22, 2008   Jul 23, 2008   Jul 24, 2008   Jul 25, 2008   Jul 27, 2008   Jul 28, 2008   Jul 29, 2008   Jul 30, 2008   Jul 31, 2008   Aug 1, 2008   Aug 3, 2008   Aug 4, 2008   Aug 5, 2008   Aug 6, 2008   Aug 7, 2008   Aug 8, 2008   Aug 10, 2008   Aug 11, 2008   Aug 12, 2008   Aug 13, 2008   Aug 14, 2008   Aug 15, 2008   Aug 17, 2008   Aug 18, 2008   Aug 19, 2008   Aug 20, 2008   Aug 21, 2008   Aug 22, 2008   Aug 24, 2008   Aug 25, 2008   Aug 26, 2008   Aug 27, 2008   Aug 28, 2008   Aug 29, 2008   Aug 31, 2008   Sep 1, 2008  

Subscribe to Posts [Atom]

 

Copyright 2008 BetterEditor.org