BetterEditor.org Media News
BetterEditor.org's Media News charts the latest developments in the world of magazines, books, and Internet publishing with press updates published to this feed as they are released. BetterEditor.org's Media News feed is updated daily.
Monday, July 23, 2007
SPI Dynamics Expert Researchers to Demonstrate Hacking Ajax Web Applications and the Latest in Hybrid Web Application Worm Threats at Black Hat USA 2007
SPI Dynamics Expert Researchers to Demonstrate Hacking Ajax Web Applications and the Latest in Hybrid Web Application Worm Threats at Black Hat USA 2007
Company's Security Evangelist, Michael Sutton, Will Take Part in Book Signing for the Release of, "Fuzzing: Brute Force Vulnerability Discovery"
ATLANTA, July 23 /PRNewswire/ -- S.P.I. Dynamics, Inc. (http://www.spidynamics.com/ ), the leading provider of web application security, today announced two of the company's expert researchers will highlight the latest in hacking web applications at the upcoming Black Hat USA 2007 conference at Caesar's Palace in Las Vegas, Nevada, August 1-2. Similar to last year's successful event, this year's Black Hat includes a significant number of talks focused specifically on web application security, underscoring the critical impact aggressively evolving application development technologies such as Ajax are having on today's security industry.
The popularity of Ajax is growing exponentially due to its ability to make web applications much more usable. Unfortunately, far too many people rush into Ajax development without giving proper consideration to the overwhelming possibility of security ramifications that stem from its ability to greatly amplify the same types of common vulnerabilities found in more traditional web applications. Bryan Sullivan, Ajax expert and Senior Security Researcher for SPI Dynamics' SPI Labs research division, will present alongside the Lead SPI Labs Security Researcher and Ajax expert, Billy Hoffman, on Ajax security. The talk titled, "Premature Ajax-ulation" is scheduled during the Black Hat conference on Wednesday, August 1st from 3:15 to 4:30 p.m. PT.
This presentation will demonstrate specific Ajax application design flaws that stem from a disregard for security including improper use of client-side XSLT, use of overly- or underly-granular server-side APIs, and storing secrets (either data or functionality) in client-side code. In addition, this session will demonstrate exploits of these vulnerabilities including: vastly more efficient Blind SQL and Blind XPath injection techniques, detecting and exploiting race conditions, and applying static analysis to deobfuscate client-side JavaScript. The session will also explore when to use and when to avoid the use of Ajax, and how the use of third-party frameworks can actually make matters worse since they hide potential security issues without truly resolving them.
Messrs. Sullivan and Hoffman will also debut a portion of their soon-to- be-released book titled Ajax Security published by Addison-Wesley Professional during Black Hat that will be available to conference attendees in the SPI Dynamics booth (# 9).
Hoffman will co-present another talk at the conference with John Terrill, Executive Vice President and Co-founder of Enterprise Management Technology LLC, focused on the latest in web application hybrid worms. The talk titled, "The Little Hybrid Web Worm that Could" is scheduled for Thursday, August 2nd from 11:15 a.m. to 12:30 p.m. PT. The presentation will discuss the rise in sophisticated web worm attacks over the past year with a look at some of the basic limitations in their methods, including the ability to detect these worms using signatures, making them annoying but ultimately controllable. The presentation will examine the possible evolution of web worms to overcome these limitations, with a description of a hybrid web worm combining both server-side and client side languages to exploit both the web server and the web browser to aid in its propagation across multiple hosts. The presentation will also take a look at how a hybrid web worm could upgrade its infection methods while in the wild by fetching and parsing new web vulnerability information from public security sites, preventing a single silver bullet fix from stopping its propagation, and how web worms could implement polymorphism and source code mutation to evade signature detection systems.
Messrs. Hoffman and Terrill will demo different parts of the worm in isolation to show how its features would function, with a specific look at how the worm could upgrade itself with publicly available vulnerability data, as well as source code mutation. Based on methodology from the JavaScript vulnerability scanner Jikto, Messrs. Hoffman and Terrill will demonstrate DOMinatrix, a JavaScript payload using SQL Injection, to extract information from a web site's database. Finally, the presentation will discuss steps to prevent hybrid web worms from exploiting a web site or its users.
In addition, SPI Dynamics' Security Evangelist, Michael Sutton, will participate in a book signing at Black Hat for the new release of his book titled, Fuzzing: Brute Force Vulnerability Discovery, published by Addison Wesley Professional and co-authored by Pedram Amini and Adam Greene. The signing will take place on Wednesday, August 1st from 3:00 p.m. to 3:15 p.m. PT. For more information on Fuzzing: Brute Force Vulnerability Discovery, please visit http://www.awprofessional.com/bookstore/product.asp?isbn=0321446119&rl=1 .
For more information on SPI Dynamics, please visit http://www.spidynamics.com/ .
About S.P.I. Dynamics, Inc.
SPI Dynamics' comprehensive suite of products and services identify and remediate web application and web services security vulnerabilities throughout the application development lifecycle. These award-winning solutions also enable security professionals, QA testers, and developers to work together to verify compliance with 22 security policies such as SOX, HIPAA and PCI. SPI Dynamics has the most application security testing customers worldwide - over 1,000 clients among Global 2000 enterprises, including four out of five of the world's largest banks and nine out of 10 of the largest banks in the U.S., four out of five of the largest software companies, three out of four of the largest aerospace and defense companies, the four largest accounting firms, the five largest telecommunications companies in the U.S., six out of eight of the largest technology hardware and equipment companies, two out of three of the largest healthcare companies, and over 90 U.S. Federal agencies. The Company is one of the fastest growing in the security industry, ranked 83rd on Deloitte's "Fast 500" list of growing technology companies nationwide and 220th on the Inc. 500. SPI Dynamics has strategic partnerships with Microsoft, IBM, HP and Visa. The Company's R&D team, SPI Labs, is widely recognized as one of the leading authorities on web application security and risk management. For more information, visit www.spidynamics.com or call (866) 774-2700.
Product or service names mentioned herein are the trademarks of their respective owners.
First Call Analyst:
FCMN Contact:
Source: S.P.I. Dynamics, Inc.
CONTACT: Michelle Schafer of Merritt Group, +1-703-390-1525, cell,
+1-703-403-6377, schafer@merrittgrp.com; or Ashley Vandiver of SPI Dynamics,
+1-678-781-4841, cell, +1-404-432-8657, avandiver@spidynamics.com
Web site:
http://www.spidynamics.com/
http://www.awprofessional.com/bookstore/product.asp?isbn=0321446119&rl=1
-------
Profile: Media News
Archives
Jul 9, 2007
Jul 10, 2007
Jul 11, 2007
Jul 12, 2007
Jul 13, 2007
Jul 15, 2007
Jul 16, 2007
Jul 17, 2007
Jul 18, 2007
Jul 19, 2007
Jul 20, 2007
Jul 21, 2007
Jul 22, 2007
Jul 23, 2007
Jul 24, 2007
Jul 25, 2007
Jul 26, 2007
Jul 27, 2007
Jul 29, 2007
Jul 30, 2007
Jul 31, 2007
Aug 1, 2007
Aug 2, 2007
Aug 3, 2007
Aug 6, 2007
Aug 7, 2007
Aug 8, 2007
Aug 9, 2007
Aug 10, 2007
Aug 12, 2007
Aug 13, 2007
Aug 14, 2007
Aug 15, 2007
Aug 16, 2007
Aug 17, 2007
Aug 20, 2007
Aug 21, 2007
Aug 22, 2007
Aug 23, 2007
Aug 24, 2007
Aug 27, 2007
Aug 28, 2007
Aug 29, 2007
Aug 30, 2007
Aug 31, 2007
Sep 3, 2007
Sep 4, 2007
Sep 5, 2007
Sep 6, 2007
Sep 7, 2007
Sep 9, 2007
Sep 10, 2007
Sep 11, 2007
Sep 12, 2007
Sep 13, 2007
Sep 14, 2007
Sep 15, 2007
Sep 16, 2007
Sep 17, 2007
Sep 18, 2007
Sep 19, 2007
Sep 20, 2007
Sep 21, 2007
Sep 23, 2007
Sep 24, 2007
Sep 25, 2007
Sep 26, 2007
Sep 27, 2007
Sep 28, 2007
Oct 1, 2007
Oct 2, 2007
Oct 3, 2007
Oct 4, 2007
Oct 5, 2007
Oct 7, 2007
Oct 8, 2007
Oct 9, 2007
Oct 10, 2007
Oct 11, 2007
Oct 12, 2007
Oct 14, 2007
Oct 15, 2007
Oct 16, 2007
Oct 17, 2007
Oct 18, 2007
Oct 19, 2007
Oct 20, 2007
Oct 21, 2007
Oct 22, 2007
Oct 23, 2007
Oct 24, 2007
Oct 25, 2007
Oct 26, 2007
Oct 28, 2007
Oct 29, 2007
Oct 30, 2007
Oct 31, 2007
Nov 1, 2007
Nov 2, 2007
Nov 3, 2007
Nov 5, 2007
Nov 6, 2007
Nov 7, 2007
Nov 8, 2007
Nov 9, 2007
Nov 10, 2007
Nov 11, 2007
Nov 12, 2007
Nov 13, 2007
Nov 14, 2007
Nov 15, 2007
Nov 16, 2007
Nov 18, 2007
Nov 19, 2007
Nov 20, 2007
Nov 21, 2007
Nov 22, 2007
Nov 25, 2007
Nov 26, 2007
Nov 27, 2007
Nov 28, 2007
Nov 29, 2007
Nov 30, 2007
Dec 2, 2007
Dec 3, 2007
Dec 4, 2007
Dec 5, 2007
Dec 6, 2007
Dec 7, 2007
Dec 10, 2007
Dec 11, 2007
Dec 12, 2007
Dec 13, 2007
Dec 14, 2007
Dec 16, 2007
Dec 17, 2007
Dec 18, 2007
Dec 19, 2007
Dec 20, 2007
Dec 21, 2007
Dec 24, 2007
Dec 25, 2007
Dec 26, 2007
Dec 27, 2007
Dec 28, 2007
Dec 31, 2007
Jan 2, 2008
Jan 3, 2008
Jan 4, 2008
Jan 6, 2008
Jan 7, 2008
Jan 8, 2008
Jan 9, 2008
Jan 10, 2008
Jan 11, 2008
Jan 12, 2008
Jan 13, 2008
Jan 14, 2008
Jan 15, 2008
Jan 16, 2008
Jan 17, 2008
Jan 18, 2008
Jan 20, 2008
Jan 21, 2008
Jan 22, 2008
Jan 23, 2008
Jan 24, 2008
Jan 25, 2008
Jan 27, 2008
Jan 28, 2008
Jan 29, 2008
Jan 30, 2008
Jan 31, 2008
Feb 1, 2008
Feb 2, 2008
Feb 3, 2008
Feb 4, 2008
Feb 5, 2008
Feb 6, 2008
Feb 7, 2008
Feb 8, 2008
Feb 10, 2008
Feb 11, 2008
Feb 12, 2008
Feb 13, 2008
Feb 14, 2008
Feb 15, 2008
Feb 16, 2008
Feb 17, 2008
Feb 18, 2008
Feb 19, 2008
Feb 20, 2008
Feb 21, 2008
Feb 22, 2008
Feb 23, 2008
Feb 24, 2008
Feb 25, 2008
Feb 26, 2008
Feb 27, 2008
Feb 28, 2008
Feb 29, 2008
Mar 1, 2008
Mar 2, 2008
Mar 3, 2008
Mar 4, 2008
Mar 5, 2008
Mar 6, 2008
Mar 7, 2008
Mar 10, 2008
Mar 11, 2008
Mar 12, 2008
Mar 13, 2008
Mar 14, 2008
Mar 15, 2008
Mar 16, 2008
Mar 17, 2008
Mar 18, 2008
Mar 19, 2008
Mar 20, 2008
Mar 21, 2008
Mar 23, 2008
Mar 24, 2008
Mar 25, 2008
Mar 26, 2008
Mar 27, 2008
Mar 28, 2008
Mar 30, 2008
Mar 31, 2008
Apr 1, 2008
Apr 2, 2008
Apr 3, 2008
Apr 4, 2008
Apr 5, 2008
Apr 6, 2008
Apr 7, 2008
Apr 8, 2008
Apr 9, 2008
Apr 10, 2008
Apr 11, 2008
Apr 13, 2008
Apr 14, 2008
Apr 15, 2008
Apr 16, 2008
Apr 17, 2008
Apr 18, 2008
Apr 19, 2008
Apr 20, 2008
Apr 21, 2008
Apr 22, 2008
Apr 23, 2008
Apr 24, 2008
Apr 25, 2008
Apr 27, 2008
Apr 28, 2008
Apr 29, 2008
Apr 30, 2008
May 1, 2008
May 2, 2008
May 4, 2008
May 5, 2008
May 6, 2008
May 7, 2008
May 8, 2008
May 9, 2008
May 10, 2008
May 11, 2008
May 12, 2008
May 13, 2008
May 14, 2008
May 15, 2008
May 16, 2008
May 18, 2008
May 19, 2008
May 20, 2008
May 21, 2008
May 22, 2008
May 23, 2008
May 26, 2008
May 27, 2008
May 28, 2008
May 29, 2008
May 30, 2008
Jun 1, 2008
Jun 2, 2008
Jun 3, 2008
Jun 4, 2008
Jun 5, 2008
Jun 6, 2008
Jun 7, 2008
Jun 8, 2008
Jun 9, 2008
Jun 10, 2008
Jun 11, 2008
Jun 12, 2008
Jun 13, 2008
Jun 14, 2008
Jun 15, 2008
Jun 16, 2008
Jun 17, 2008
Jun 18, 2008
Jun 19, 2008
Jun 20, 2008
Jun 23, 2008
Jun 24, 2008
Jun 25, 2008
Jun 26, 2008
Jun 27, 2008
Jun 29, 2008
Jun 30, 2008
Jul 1, 2008
Jul 2, 2008
Jul 3, 2008
Jul 4, 2008
Jul 6, 2008
Jul 7, 2008
Jul 8, 2008
Jul 9, 2008
Jul 10, 2008
Jul 11, 2008
Jul 13, 2008
Jul 14, 2008
Jul 15, 2008
Jul 16, 2008
Jul 17, 2008
Jul 18, 2008
Jul 20, 2008
Jul 21, 2008
Jul 22, 2008
Jul 23, 2008
Jul 24, 2008
Jul 25, 2008
Jul 27, 2008
Jul 28, 2008
Jul 29, 2008
Jul 30, 2008
Jul 31, 2008
Aug 1, 2008
Aug 3, 2008
Aug 4, 2008
Aug 5, 2008
Aug 6, 2008
Aug 7, 2008
Aug 8, 2008
Aug 10, 2008
Aug 11, 2008
Aug 12, 2008
Aug 13, 2008
Aug 14, 2008
Aug 15, 2008
Aug 17, 2008
Aug 18, 2008
Aug 19, 2008
Aug 20, 2008
Aug 21, 2008
Aug 22, 2008
Aug 24, 2008
Aug 25, 2008
Aug 26, 2008
Aug 27, 2008
Aug 28, 2008
Aug 29, 2008
Aug 31, 2008
Sep 1, 2008
Subscribe to Posts [Atom]