<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>SecDocs Feed for author Cesar Cerrudo</title>
    <link>http://secdocs.lonerunners.net</link>
    <atom:link type="application/rss+xml" href="http://secdocs.lonerunners.net/rss/author/75-cesar-cerrudo" rel="self"/>
    <description>Latest security documents RSS feed for author Cesar Cerrudo</description>
    <language>en-us</language>
    <item>
      <title>[Slides] WLSI - Windows Local Shellcode Injection</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/75-cesar-cerrudo"&gt;Cesar Cerrudo&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/34-shellcode"&gt;shellcode&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/96-black-hat-eu-2006"&gt;Black Hat EU 2006&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Fri, 13 Jan 2012 06:34:03 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/4730-wlsi---windows-local-shellcode-injection</link>
      <guid>http://secdocs.lonerunners.net/documents/details/4730-wlsi---windows-local-shellcode-injection</guid>
    </item>
    <item>
      <title>[Slides] Hacking Windows Internals</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/75-cesar-cerrudo"&gt;Cesar Cerrudo&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/45-windows"&gt;Windows&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/tags/details/83-exploiting"&gt;exploiting&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/93-black-hat-eu-2005"&gt;Black Hat EU 2005&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Tue, 27 Dec 2011 06:34:16 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/4628-hacking-windows-internals</link>
      <guid>http://secdocs.lonerunners.net/documents/details/4628-hacking-windows-internals</guid>
    </item>
    <item>
      <title>[Slides] Demystifying MS SQL Server &amp; Oracle Database Server Security</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/75-cesar-cerrudo"&gt;Cesar Cerrudo&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/7-sql-server"&gt;SQL Server&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/tags/details/9-oracle"&gt;Oracle&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/92-black-hat-usa-2005"&gt;Black Hat USA 2005&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Sat, 24 Dec 2011 06:28:30 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/4608-demystifying-ms-sql-server--oracle-database-server-security</link>
      <guid>http://secdocs.lonerunners.net/documents/details/4608-demystifying-ms-sql-server--oracle-database-server-security</guid>
    </item>
    <item>
      <title>[Slides] Auditing ActiveX Controls</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/75-cesar-cerrudo"&gt;Cesar Cerrudo&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/79-activex"&gt;ActiveX&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/90-black-hat-windows-security-2004"&gt;Black Hat Windows Security 2004&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Tue, 13 Dec 2011 06:33:15 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/4539-auditing-activex-controls</link>
      <guid>http://secdocs.lonerunners.net/documents/details/4539-auditing-activex-controls</guid>
    </item>
    <item>
      <title>[Slides] Hunting Flaws in MS SQL Server</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/5-aaron-newman"&gt;Aaron Newman&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/authors/details/75-cesar-cerrudo"&gt;Cesar Cerrudo&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/7-sql-server"&gt;SQL Server&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/76-black-hat-windows-security-2003"&gt;Black Hat Windows Security 2003&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Thu, 20 Oct 2011 08:54:07 +0200</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/4199-hunting-flaws-in-ms-sql-server</link>
      <guid>http://secdocs.lonerunners.net/documents/details/4199-hunting-flaws-in-ms-sql-server</guid>
    </item>
    <item>
      <title>[Paper] Hunting Flaws in MS SQL Server</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/5-aaron-newman"&gt;Aaron Newman&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/authors/details/75-cesar-cerrudo"&gt;Cesar Cerrudo&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/7-sql-server"&gt;SQL Server&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/76-black-hat-windows-security-2003"&gt;Black Hat Windows Security 2003&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Thu, 20 Oct 2011 08:54:07 +0200</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/4200-hunting-flaws-in-ms-sql-server</link>
      <guid>http://secdocs.lonerunners.net/documents/details/4200-hunting-flaws-in-ms-sql-server</guid>
    </item>
    <item>
      <title>[Paper] Token Kidnapping's Revenge</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/75-cesar-cerrudo"&gt;Cesar Cerrudo&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/45-windows"&gt;Windows&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/tags/details/83-exploiting"&gt;exploiting&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/71-black-hat-usa-2010"&gt;Black Hat USA 2010&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Abstract&lt;/b&gt;: On April 14, 2009 Microsoft released a patch (documented here) to fix the issues detailed in my previous Token Kidnapping presentation (download PDF). The patch properly fixed the issues but...  This new presentation will detail new design mistakes and security issues that can be exploited to elevate privileges on all Windows versions including the brand new Windows 2008 R2 and Windows 7. These new attacks allow to bypass new Windows services protections such as Per service SID, Write restricted token, etc. It will be demonstrated that almost any process with impersonation rights can elevate privileges to Local System account and completely compromise Windows OSs. While the issues are not critical in nature since impersonation rights are required, they allow to exploit services such as IIS 6, IIS 7, SQL Server, etc. in some specific scenarios. Exploits code for those services will be released. The presentation will be given in a very practical way showing how the new issues were found, with what tools, techniques, etc. allowing the participants to learn how to easily find these kind security issues in Windows operating systems.</description>
      <pubDate>Wed, 07 Sep 2011 19:04:26 +0200</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/3974-token-kidnappings-revenge</link>
      <guid>http://secdocs.lonerunners.net/documents/details/3974-token-kidnappings-revenge</guid>
    </item>
    <item>
      <title>[Slides] Token Kidnapping's Revenge</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/75-cesar-cerrudo"&gt;Cesar Cerrudo&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/45-windows"&gt;Windows&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/tags/details/83-exploiting"&gt;exploiting&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/71-black-hat-usa-2010"&gt;Black Hat USA 2010&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Abstract&lt;/b&gt;: On April 14, 2009 Microsoft released a patch (documented here) to fix the issues detailed in my previous Token Kidnapping presentation (download PDF). The patch properly fixed the issues but...  This new presentation will detail new design mistakes and security issues that can be exploited to elevate privileges on all Windows versions including the brand new Windows 2008 R2 and Windows 7. These new attacks allow to bypass new Windows services protections such as Per service SID, Write restricted token, etc. It will be demonstrated that almost any process with impersonation rights can elevate privileges to Local System account and completely compromise Windows OSs. While the issues are not critical in nature since impersonation rights are required, they allow to exploit services such as IIS 6, IIS 7, SQL Server, etc. in some specific scenarios. Exploits code for those services will be released. The presentation will be given in a very practical way showing how the new issues were found, with what tools, techniques, etc. allowing the participants to learn how to easily find these kind security issues in Windows operating systems.</description>
      <pubDate>Wed, 07 Sep 2011 19:04:10 +0200</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/3973-token-kidnappings-revenge</link>
      <guid>http://secdocs.lonerunners.net/documents/details/3973-token-kidnappings-revenge</guid>
    </item>
    <item>
      <title>[Paper] Practical 10 Minute Security Audit: The Oracle Case</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/75-cesar-cerrudo"&gt;Cesar Cerrudo&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/9-oracle"&gt;Oracle&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/70-black-hat-dc-2007"&gt;Black Hat DC 2007&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Thu, 28 Jul 2011 21:15:47 +0200</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/3896-practical-10-minute-security-audit-the-oracle-case</link>
      <guid>http://secdocs.lonerunners.net/documents/details/3896-practical-10-minute-security-audit-the-oracle-case</guid>
    </item>
    <item>
      <title>[Slides] Practical 10 Minute Security Audit: The Oracle Case</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/75-cesar-cerrudo"&gt;Cesar Cerrudo&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/9-oracle"&gt;Oracle&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/70-black-hat-dc-2007"&gt;Black Hat DC 2007&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Thu, 28 Jul 2011 21:15:15 +0200</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/3895-practical-10-minute-security-audit-the-oracle-case</link>
      <guid>http://secdocs.lonerunners.net/documents/details/3895-practical-10-minute-security-audit-the-oracle-case</guid>
    </item>
    <item>
      <title>[Paper] Hacking Databases for Owning Your Data</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/75-cesar-cerrudo"&gt;Cesar Cerrudo&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/authors/details/1118-esteban-mart%C3%ADnez-fay%C3%B3"&gt;Esteban Mart&#237;nez Fay&#243;&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/3-database"&gt;database&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/tags/details/70-sql-injection"&gt;SQL injection&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/69-black-hat-eu-2007"&gt;Black Hat EU 2007&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Fri, 08 Jul 2011 01:04:35 +0200</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/3858-hacking-databases-for-owning-your-data</link>
      <guid>http://secdocs.lonerunners.net/documents/details/3858-hacking-databases-for-owning-your-data</guid>
    </item>
    <item>
      <title>[Slides] Hacking Databases for Owning Your Data</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/75-cesar-cerrudo"&gt;Cesar Cerrudo&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/authors/details/1118-esteban-mart%C3%ADnez-fay%C3%B3"&gt;Esteban Mart&#237;nez Fay&#243;&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/3-database"&gt;database&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/tags/details/70-sql-injection"&gt;SQL injection&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/69-black-hat-eu-2007"&gt;Black Hat EU 2007&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Fri, 08 Jul 2011 01:04:18 +0200</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/3857-hacking-databases-for-owning-your-data</link>
      <guid>http://secdocs.lonerunners.net/documents/details/3857-hacking-databases-for-owning-your-data</guid>
    </item>
    <item>
      <title>[Video] Token Kidnapping's Revenge</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/75-cesar-cerrudo"&gt;Cesar Cerrudo&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/45-windows"&gt;Windows&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/tags/details/83-exploiting"&gt;exploiting&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/65-defcon-18"&gt;DEFCON 18&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Sat, 29 Jan 2011 12:19:50 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/3351-token-kidnappings-revenge</link>
      <guid>http://secdocs.lonerunners.net/documents/details/3351-token-kidnappings-revenge</guid>
    </item>
    <item>
      <title>[Paper] Token Kidnapping's Revenge</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/75-cesar-cerrudo"&gt;Cesar Cerrudo&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/45-windows"&gt;Windows&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/tags/details/83-exploiting"&gt;exploiting&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/65-defcon-18"&gt;DEFCON 18&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Sat, 29 Jan 2011 12:01:21 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/3350-token-kidnappings-revenge</link>
      <guid>http://secdocs.lonerunners.net/documents/details/3350-token-kidnappings-revenge</guid>
    </item>
    <item>
      <title>[Slides] Token Kidnapping's Revenge</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/75-cesar-cerrudo"&gt;Cesar Cerrudo&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/45-windows"&gt;Windows&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/tags/details/83-exploiting"&gt;exploiting&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/65-defcon-18"&gt;DEFCON 18&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Sat, 29 Jan 2011 12:01:02 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/3349-token-kidnappings-revenge</link>
      <guid>http://secdocs.lonerunners.net/documents/details/3349-token-kidnappings-revenge</guid>
    </item>
    <item>
      <title>[Audio] Token Kidnapping's Revenge</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/75-cesar-cerrudo"&gt;Cesar Cerrudo&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/45-windows"&gt;Windows&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/tags/details/83-exploiting"&gt;exploiting&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/65-defcon-18"&gt;DEFCON 18&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Sat, 29 Jan 2011 12:00:33 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/3348-token-kidnappings-revenge</link>
      <guid>http://secdocs.lonerunners.net/documents/details/3348-token-kidnappings-revenge</guid>
    </item>
    <item>
      <title>[Slides] SQL Server Anti-Forensics</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/75-cesar-cerrudo"&gt;Cesar Cerrudo&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/7-sql-server"&gt;SQL Server&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/tags/details/8-forensic"&gt;forensic&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/15-black-hat-dc-2009"&gt;Black Hat DC 2009&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Tue, 31 Aug 2010 11:17:00 +0200</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/2838-sql-server-anti-forensics</link>
      <guid>http://secdocs.lonerunners.net/documents/details/2838-sql-server-anti-forensics</guid>
    </item>
    <item>
      <title>[Audio] SQL Server Anti-Forensics</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/75-cesar-cerrudo"&gt;Cesar Cerrudo&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/7-sql-server"&gt;SQL Server&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/tags/details/8-forensic"&gt;forensic&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/15-black-hat-dc-2009"&gt;Black Hat DC 2009&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Tue, 31 Aug 2010 11:17:00 +0200</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/2839-sql-server-anti-forensics</link>
      <guid>http://secdocs.lonerunners.net/documents/details/2839-sql-server-anti-forensics</guid>
    </item>
    <item>
      <title>[Video] SQL Server Anti-Forensics</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/75-cesar-cerrudo"&gt;Cesar Cerrudo&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/7-sql-server"&gt;SQL Server&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/tags/details/8-forensic"&gt;forensic&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/15-black-hat-dc-2009"&gt;Black Hat DC 2009&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Tue, 31 Aug 2010 11:17:00 +0200</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/2840-sql-server-anti-forensics</link>
      <guid>http://secdocs.lonerunners.net/documents/details/2840-sql-server-anti-forensics</guid>
    </item>
    <item>
      <title>[Paper] SQL Server Anti-Forensics</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/75-cesar-cerrudo"&gt;Cesar Cerrudo&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/7-sql-server"&gt;SQL Server&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/tags/details/8-forensic"&gt;forensic&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/15-black-hat-dc-2009"&gt;Black Hat DC 2009&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Thu, 19 Feb 2009 13:30:00 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/389-sql-server-anti-forensics</link>
      <guid>http://secdocs.lonerunners.net/documents/details/389-sql-server-anti-forensics</guid>
    </item>
    <item>
      <title>[Paper] Manipulating Microsoft SQL Server Using SQL Injection</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/75-cesar-cerrudo"&gt;Cesar Cerrudo&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/7-sql-server"&gt;SQL Server&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/tags/details/70-sql-injection"&gt;SQL injection&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/tags/details/83-exploiting"&gt;exploiting&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Sun, 08 Jun 2008 16:23:00 +0200</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/210-manipulating-microsoft-sql-server-using-sql-injection</link>
      <guid>http://secdocs.lonerunners.net/documents/details/210-manipulating-microsoft-sql-server-using-sql-injection</guid>
    </item>
    <item>
      <title>[Paper] Manipulating Microsoft SQL Server Using SQL Injection</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/75-cesar-cerrudo"&gt;Cesar Cerrudo&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/7-sql-server"&gt;SQL Server&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/tags/details/70-sql-injection"&gt;SQL injection&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Abstract&lt;/b&gt;: This paper will not cover basic SQL syntax or SQL Injection. It is assumed that the reader has a strong understanding of these topics already. This paper will focus on advanced techniques that can be used in an attack on a (web) application utilizing Microsoft SQL Server as a backend. These techniques demonstrate how an attacker could use a SQL Injection vulnerability to retrieve the database content from behind a firewall and penetrate the internal network. This paper is meant to educate security professionals of the potential devastating effects SQL Injection could have on an organization. Web applications are becoming more secure because of the growing awareness of attacks such as SQL Injection. However, in large and complex applications, a single oversight can result in the compromise of the entire system. Specifically, many developers and administrators of (web) applications may have a false sense of security because they use stored procedures or mask an error messages returned to the browser. This may lead them to believe that they can not be compromised by this vulnerability. While we discuss Microsoft SQL Server in this paper, this is no way indicative that Microsoft SQL Server is any less secure than other database platforms such as Oracle or IBM DB2. SQL injection is not a defect of Microsoft SQL Server &#8211; it is also a problem for every other database vendor as well. Perhaps the biggest issue with Microsoft SQL Server is the flexibility of the system. This flexibility is what allows it to be subverted so far by SQL injection. This paper is meant to show that any time an administrator or developer allows arbitrary SQL to be executed, their system is open to being rooted. It is not meant to show that Microsoft SQL Server is inherently flawed.</description>
      <pubDate>Sat, 26 Apr 2008 13:50:00 +0200</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/198-manipulating-microsoft-sql-server-using-sql-injection</link>
      <guid>http://secdocs.lonerunners.net/documents/details/198-manipulating-microsoft-sql-server-using-sql-injection</guid>
    </item>
    <item>
      <title>[Slides] Token Kidnapping</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/75-cesar-cerrudo"&gt;Cesar Cerrudo&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/45-windows"&gt;Windows&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/tags/details/83-exploiting"&gt;exploiting&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/tags/details/122-internals"&gt;internals&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/tags/details/123-windows-vista"&gt;Windows Vista&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Sun, 20 Apr 2008 00:29:00 +0200</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/195-token-kidnapping</link>
      <guid>http://secdocs.lonerunners.net/documents/details/195-token-kidnapping</guid>
    </item>
  </channel>
</rss>

