October 11th - Web 2.0 Security - Defending Next Generation Applications

Client-side attack vectors are on the rise - from XSS to RSS, from Widget injections to Mashup manipulations. At the same time, various new attack vectors are evolving around SOA by attacking SOAP, XML-RPC and REST. At the workshop, you will experience real-life cases, hands-on exercises, new scanning tools and critical defense mechanisms by Mr. Shreeraj Shah.

Topics Covered

  • Web 2.0 security fundamentals and protocols.
  • Application architecture: .NET and J2EE application frameworks, Web 2.0 application architecture, Widgets framework, application layers and components, resources and interactions, other languages.
  • Application attack vectors: SQL injection, Cross Site Scripting (XSS), Cross Site Request Forgery (CSRF), path traversal, session hijacking, LDAP/XPATH/Command injection, buffer overflow, input validation bypassing, database hacks and blind SQL injections.
  • Advanced attacks: Ajax-based XSS, CSRF with Web services, decompiling Flash and RIA apps, WSDL scanning, XML poisoning, SQL injections through XML, external entity attacks, Widget exploitation, RSS injections, Cross Domain bypass, and many more.
  • Advanced application foot printing and discovery: leveraging search engines, cross domain mashup discovery and Web 2.0 application domain enumeration .
  • Methodologies: fingerprinting Web and application server, Ajax framework, Flash-based application and technology fingerprinting, advanced browser-based attacks and vulnerability detection.
  • Scanning Web services (including XML-RPC, SOAP and REST-based applications) for vulnerabilities through source code by looking at function and method signature mapping, entry point identification, data access layer calls, tracing variables and functions.
  • Applying validations: input, output, data access filtering, and authentication validations, as well as advanced content filtering.

Who should attend?

Developers, Web Administrators, Security Auditors, Pen-Testers and Program Managers.

Event details

Date 11th October, 2008
Time 2pm - 6pm
Venue Club Link, Link Road, Malad (West), Mumbai 400 064

View the Pics

www.flickr.com

The Presentation

  Name Size Creator (Last Modifier) Creation Date Last Mod Date Comment  
PDF File ShreerajTechCamp.pdf 1.97 Mb Anusha Pinto (modified by Anusha Pinto) Oct 14, 2008 Oct 14, 2008  

How can you attend the event?

Simply fill in your details below.


This event is currently full.
Name Company
Abhijit Bhatnagar   Directi 
Abhilash Puthoor    
Abhishek Sugandhi   Webaroo Inc. 
Ajay Mahale   Directi 
Ajinkya Deshpande   Master Technologies 
Alexine Dsouza   Directi 
Allan Pereira   WOI 
Aniketh Patrick   - 
Anish Abraham   Atos Origin 
Ankit Agarwal   GE 
Ashish Lakhotia   Infinite Computing Systems 
Atul Kapoor   slash-junk 
Bhavin Turakhia  Directi 
Christin John   Webaroo Inc. 
darshit khatri  Directi 
Deepak Bhat  Directi 
Dhairya Dand    
Dharmesh Sejpal   ThoughtWorks 
Dinesh Dalvi   Computer World 
Dinesh Gunasekar   Hostway Solutions Pvt. Ltd. 
Gorbachev Anthony   Directi 
Gur Kamal Singh Badal  Directi 
Husain   Infosys 
Jalpesh Rajani   WOI 
Jeetendra  DirectI 
Joel Rosario   Directi 
Kamlesh Shah   Parth Information Technology 
Kanchan Talreja   DSS 
Karthik Iyer   Directi 
Kartik Maguwala  Directi 
Keyur Makwana  Directi 
Laxmikant Purohit   DSS 
Lokesh Chauhan   Indipepal 
Makwana Sachin   Grey Matter India Pvt Ltd. 
Mandakini Mehta   Tech Mahindra 
Mayur Gurav  DirectI 
Mohit R. Jain   WOI 
Mukesh   Version next 
Nicholas    
Nilesh Mevada  Directi 
Nitin Bhamvani    
Om Sharma  DirectI 
Pradyumn Sharma   Pragati Software Pvt Ltd 
Pradyumna    
Prashant   Elite systems 
Pravin Rane    
Preshit   MobileIndustryReview 
rahul mal   
Raza Z Sayed    
Sachin Waingankar   Netmagic Solutions Pvt. Ltd. 
Sandeep Pillai    
Sanjeev Mishra   
Sankalp Kohli    
Santosh Gokak   Mastek 
Shaikh Aheteshamodin   WOI 
Shamshuddin Shaikh   Perimeter 
Shiban Sayed   Webaroo Inc. 
Steeve Goveas  Directi 
Sumant Kumar  Accenture 
Sushanth Poojary    
Swapnil Gawas    
Tanuj Hattangdi    
Vikrant Rao  DirectI 
Vinayak   Pinstorm 
Vishal Uderani  Directi 
Vivek Kumar   
Yesudeep Mangalapilly   HappyChickoo 
zakir shaikh  Directi 

  • Please note that you will be added to the Techcamp mailing list to be notified about future TechCamp events.

About the Speaker

Shreeraj Shah, B.E., MSCS, MBA, is the founder of Blueinfy, a company that provides application security services. Prior to founding Blueinfy, he was founder and board member at Net Square. He also worked with Foundstone (McAfee), Chase Manhattan Bank and IBM in security space.

He is also the author of popular books like Hacking Web Services (Thomson 06) and Web Hacking: Attacks and Defense (Addison-Wesley 03). In addition, he has published several advisories, tools, and whitepapers, and has presented at numerous conferences including RSA, AusCERT, InfosecWorld (Misti), HackInTheBox, Blackhat, OSCON, Bellua, Syscan, ISACA etc. His articles are regularly published on Securityfocus, InformIT, DevX, O'reilly, HNS. His work has been quoted on BBC, Dark Reading, Bank Technology as an expert.

Shreeraj was instrumental in product development, researching new methodologies and training designs. He has performed several security consulting assignments in the area of penetration testing, code reviews, web application assessments, security architecture reviews and managing projects

Labels

 
  1. Sep 22, 2008

    Sanjeev Mishra says:

    Hi, I have logged in, but apparantly i am not able to add my name ( edit this pa...

    Hi,

    I have logged in, but apparantly i am not able to add my name ( edit this page). Please add me as one of the participants to the event.

    Thx 

    1. Sep 24, 2008

      Shaheen Peerbhai says:

      Hi Sanjeev,  You need to click on "Attend event" and not edit the page to h...

      Hi Sanjeev,

       You need to click on "Attend event" and not edit the page to have your name appear on the list of attendees. Nonetheless, I've added your name.

  2. Sep 23, 2008

    Anonymous says:

    guys, attendees list is displaying email ids to the public. someone can look int...

    guys, attendees list is displaying email ids to the public. someone can look into this.

    --rats

  3. Oct 09, 2008

    Anonymous says:

    Is this a public event are students eligible to be part of it and is there a fee...

    Is this a public event are students eligible to be part of it and is there a fee to attend the event

  4. Oct 10, 2008

    Vishal Uderani says:

    I dont think this is a paid event and Directi welcomes everyone to join :D

    I dont think this is a paid event and Directi welcomes everyone to join

 

Life@Directi


From Blogs & Wikis

Directi Presentations

General Wikis

Directi Univ Wikis

Company Blogs

Businesses


TechCamp
Start.pw - Coming Soon! LogicBoxes - Registry & Registrar Solutions ResellerClub - Domain Reseller, Domain Name Reseller, Cheap Domain Reseller - Resellers Skenzo - Exclusive Traffic Monetization Programs WebHosting - Web Hosting Information CodeChef - Online Programming Competition
All content in the Directi Wiki is licensed under a Creative Commons Attribution-Share Alike 3.0 License.