Advanced SQL Injection

DEF CON 17

Presented by: Tobias Bluzmanis
Date: Sunday August 02, 2009
Time: 10:00 - 10:50
Location: Turbo/Breakout Track
Track: Turbo/Breakout

SQL Injection is a vulnerability that is often missed by web application security scanners, and it's a vulnerability that is often rated as NOT exploitable by security testers when it actually can be exploited.

Advanced SQL Injection is a presentation geared toward showing security professionals advanced exploitation techniques for situations when you must prove to the customer the extent of compromise that is possible.

The key areas are:

Joseph McCray

<strong>Joseph McCray</strong> has 8 years of experience in the security industry with a diverse background that includes network and web application penetration testing, forensics, training, and regulatory compliance. Joe is a frequent presenter at security conferences, and has taught the CISSP, CEH, CHFI, and Web Application Security at Johns Hopkins University (JHU), University of Maryland Baltimore College (UMBC), and several other technical training centers across the country.


KhanFu - Mobile schedules for INFOSEC conferences.
Mobile interface | Alternate Formats