Attacking Drupal

BSidesLV 2014

Presented by: Greg Foss (ˀ)
Date: Wednesday August 06, 2014
Time: 14:00 - 14:30
Location: Proving Ground

Drupal is a very popular content management system that has been widely adopted by government agencies, major businesses, social networks, and more -- underscoring why understanding how Drupal works and properly securing these applications is of the utmost importance. This talk focuses on the penetration tester's perspective of Drupal and dives into streamlining the assessment and remediation of commonly observed application and configuration flaws by way of custom exploit code and security checklists, all of which are open-source and can be downloaded and implemented following the presentation.

Greg Foss

Sr. Security Researcher, LogRhythm Labs Greg Foss is a Senior Security Research Engineer with the LogRhythm Labs Threat Intelligence Team, where he focuses on developing defensive strategies, tools and methodologies to counteract advanced attack scenarios. He has over 7 years of experience in the Information Security industry with an extensive background in Security Operations, focusing on Penetration Testing and Web Application Security. Greg holds multiple industry certifications including the OSCP, GPEN, GWAPT, GCIH, and C|EH, among others.


KhanFu - Mobile schedules for INFOSEC conferences.
Mobile interface | Alternate Formats