<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>SecDocs Feed for author Jose Palazon</title>
    <link>http://secdocs.lonerunners.net</link>
    <atom:link type="application/rss+xml" href="http://secdocs.lonerunners.net/rss/author/721-jose-palazon" rel="self"/>
    <description>Latest security documents RSS feed for author Jose Palazon</description>
    <language>en-us</language>
    <item>
      <title>[Paper] Connection String Parameter Attacks</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/598-chema-alonso"&gt;Chema Alonso&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/authors/details/721-jose-palazon"&gt;Jose Palazon&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/3-database"&gt;database&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/tags/details/13-web-application"&gt;web application&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/65-defcon-18"&gt;DEFCON 18&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Tue, 11 Jan 2011 06:08:52 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/3286-connection-string-parameter-attacks</link>
      <guid>http://secdocs.lonerunners.net/documents/details/3286-connection-string-parameter-attacks</guid>
    </item>
    <item>
      <title>[Slides] Connection String Parameter Attacks</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/598-chema-alonso"&gt;Chema Alonso&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/authors/details/721-jose-palazon"&gt;Jose Palazon&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/3-database"&gt;database&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/tags/details/13-web-application"&gt;web application&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/65-defcon-18"&gt;DEFCON 18&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Tue, 11 Jan 2011 06:08:27 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/3285-connection-string-parameter-attacks</link>
      <guid>http://secdocs.lonerunners.net/documents/details/3285-connection-string-parameter-attacks</guid>
    </item>
    <item>
      <title>[Video] Connection String Parameter Attacks</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/598-chema-alonso"&gt;Chema Alonso&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/authors/details/721-jose-palazon"&gt;Jose Palazon&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/3-database"&gt;database&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/tags/details/13-web-application"&gt;web application&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/65-defcon-18"&gt;DEFCON 18&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Tue, 11 Jan 2011 06:07:43 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/3284-connection-string-parameter-attacks</link>
      <guid>http://secdocs.lonerunners.net/documents/details/3284-connection-string-parameter-attacks</guid>
    </item>
    <item>
      <title>[Video] Connection String Parameter Attacks</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/598-chema-alonso"&gt;Chema Alonso&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/authors/details/721-jose-palazon"&gt;Jose Palazon&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/3-database"&gt;database&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/tags/details/13-web-application"&gt;web application&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/65-defcon-18"&gt;DEFCON 18&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Tue, 11 Jan 2011 05:59:46 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/3283-connection-string-parameter-attacks</link>
      <guid>http://secdocs.lonerunners.net/documents/details/3283-connection-string-parameter-attacks</guid>
    </item>
    <item>
      <title>[Video] FOCA2: The FOCA Strikes Back</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/598-chema-alonso"&gt;Chema Alonso&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/authors/details/721-jose-palazon"&gt;Jose Palazon&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/24-network"&gt;network&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/tags/details/193-privacy"&gt;privacy&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/65-defcon-18"&gt;DEFCON 18&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Tue, 11 Jan 2011 05:47:40 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/3282-foca2-the-foca-strikes-back</link>
      <guid>http://secdocs.lonerunners.net/documents/details/3282-foca2-the-foca-strikes-back</guid>
    </item>
    <item>
      <title>[Audio] FOCA2: The FOCA Strikes Back</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/598-chema-alonso"&gt;Chema Alonso&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/authors/details/721-jose-palazon"&gt;Jose Palazon&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/24-network"&gt;network&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/tags/details/193-privacy"&gt;privacy&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/65-defcon-18"&gt;DEFCON 18&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Tue, 11 Jan 2011 05:38:28 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/3281-foca2-the-foca-strikes-back</link>
      <guid>http://secdocs.lonerunners.net/documents/details/3281-foca2-the-foca-strikes-back</guid>
    </item>
    <item>
      <title>[Video] Tactical Fingerprinting Using Metadata, Hidden Info and Lost Data</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/598-chema-alonso"&gt;Chema Alonso&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/authors/details/721-jose-palazon"&gt;Jose Palazon&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/8-forensic"&gt;forensic&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/tags/details/193-privacy"&gt;privacy&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/tags/details/283-office"&gt;Office&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/39-defcon-17"&gt;DEFCON 17&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Mon, 22 Feb 2010 06:15:17 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/2077-tactical-fingerprinting-using-metadata-hidden-info-and-lost-data</link>
      <guid>http://secdocs.lonerunners.net/documents/details/2077-tactical-fingerprinting-using-metadata-hidden-info-and-lost-data</guid>
    </item>
    <item>
      <title>[Audio] Tactical Fingerprinting Using Metadata, Hidden Info and Lost Data</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/598-chema-alonso"&gt;Chema Alonso&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/authors/details/721-jose-palazon"&gt;Jose Palazon&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/8-forensic"&gt;forensic&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/tags/details/193-privacy"&gt;privacy&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/tags/details/283-office"&gt;Office&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/39-defcon-17"&gt;DEFCON 17&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Mon, 22 Feb 2010 06:15:14 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/2076-tactical-fingerprinting-using-metadata-hidden-info-and-lost-data</link>
      <guid>http://secdocs.lonerunners.net/documents/details/2076-tactical-fingerprinting-using-metadata-hidden-info-and-lost-data</guid>
    </item>
    <item>
      <title>[Paper] Tactical Fingerprinting Using Metadata, Hidden Info and Lost Data</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/598-chema-alonso"&gt;Chema Alonso&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/authors/details/721-jose-palazon"&gt;Jose Palazon&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/8-forensic"&gt;forensic&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/tags/details/193-privacy"&gt;privacy&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/tags/details/283-office"&gt;Office&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/39-defcon-17"&gt;DEFCON 17&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Mon, 22 Feb 2010 06:15:12 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/2075-tactical-fingerprinting-using-metadata-hidden-info-and-lost-data</link>
      <guid>http://secdocs.lonerunners.net/documents/details/2075-tactical-fingerprinting-using-metadata-hidden-info-and-lost-data</guid>
    </item>
    <item>
      <title>[Slides] Tactical Fingerprinting Using Metadata, Hidden Info and Lost Data</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/598-chema-alonso"&gt;Chema Alonso&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/authors/details/721-jose-palazon"&gt;Jose Palazon&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/8-forensic"&gt;forensic&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/tags/details/193-privacy"&gt;privacy&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/tags/details/283-office"&gt;Office&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/39-defcon-17"&gt;DEFCON 17&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Mon, 22 Feb 2010 06:15:11 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/2074-tactical-fingerprinting-using-metadata-hidden-info-and-lost-data</link>
      <guid>http://secdocs.lonerunners.net/documents/details/2074-tactical-fingerprinting-using-metadata-hidden-info-and-lost-data</guid>
    </item>
    <item>
      <title>[Slides] Connection String Parameter Pollution Attacks</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/598-chema-alonso"&gt;Chema Alonso&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/authors/details/721-jose-palazon"&gt;Jose Palazon&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/3-database"&gt;database&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/tags/details/7-sql-server"&gt;SQL Server&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/tags/details/17-authentication"&gt;authentication&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/tags/details/70-sql-injection"&gt;SQL injection&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/37-black-hat-dc-2010"&gt;Black Hat DC 2010&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Abstract&lt;/b&gt;: This session is about Parameter Pollution in Connection Strings Attack. Today, a lot of tools and web applications allow users to configure dynamically a connection against a Database server. This session will demonstrate the high risk in doing this insecurely. This session will show how to steal, in Microsoft Internet Information Services, the user account credential, how to get access to this web applications impersonating the connection and taking advance of the web server credentials and how to connect against internal databases servers in the DMZ without credentials. The impact of these techniques are specially dangerous in hosting companies which allow customers to connect against control panels to configure databases.</description>
      <pubDate>Sat, 13 Feb 2010 06:10:58 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/2035-connection-string-parameter-pollution-attacks</link>
      <guid>http://secdocs.lonerunners.net/documents/details/2035-connection-string-parameter-pollution-attacks</guid>
    </item>
    <item>
      <title>[Paper] Connection String Parameter Pollution Attacks</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/598-chema-alonso"&gt;Chema Alonso&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/authors/details/721-jose-palazon"&gt;Jose Palazon&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/3-database"&gt;database&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/tags/details/7-sql-server"&gt;SQL Server&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/tags/details/17-authentication"&gt;authentication&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/tags/details/70-sql-injection"&gt;SQL injection&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/37-black-hat-dc-2010"&gt;Black Hat DC 2010&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Abstract&lt;/b&gt;: This session is about Parameter Pollution in Connection Strings Attack. Today, a lot of tools and web applications allow users to configure dynamically a connection against a Database server. This session will demonstrate the high risk in doing this insecurely. This session will show how to steal, in Microsoft Internet Information Services, the user account credential, how to get access to this web applications impersonating the connection and taking advance of the web server credentials and how to connect against internal databases servers in the DMZ without credentials. The impact of these techniques are specially dangerous in hosting companies which allow customers to connect against control panels to configure databases.</description>
      <pubDate>Sat, 13 Feb 2010 06:10:55 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/2034-connection-string-parameter-pollution-attacks</link>
      <guid>http://secdocs.lonerunners.net/documents/details/2034-connection-string-parameter-pollution-attacks</guid>
    </item>
  </channel>
</rss>

