| Date |
Type |
Title |
Author |
Event |
| April 15, 2012 |
Audio |
Contemporary Profiling of Web Users
|
Dominik Herrmann
|
Chaos Communication Congress 27th (27C3) 2010 |
| April 15, 2012 |
Video |
Contemporary Profiling of Web Users
|
Dominik Herrmann
|
Chaos Communication Congress 27th (27C3) 2010 |
| April 01, 2012 |
Audio |
New Ways I'm Going to Hack Your Web App
|
Jesse Ou
Rich Lundeen
Travis Rhodes
|
Chaos Communication Congress 28th (28C3) 2011 |
| April 01, 2012 |
Slides |
New Ways I'm Going to Hack Your Web App
|
Jesse Ou
Rich Lundeen
Travis Rhodes
|
Chaos Communication Congress 28th (28C3) 2011 |
| April 01, 2012 |
Video |
New Ways I'm Going to Hack Your Web App
|
Jesse Ou
Rich Lundeen
Travis Rhodes
|
Chaos Communication Congress 28th (28C3) 2011 |
| March 19, 2012 |
Video |
Rootkits in your Web application
|
Artur Janc
|
Chaos Communication Congress 28th (28C3) 2011 |
| March 18, 2012 |
Slides |
Rootkits in your Web application
|
Artur Janc
|
Chaos Communication Congress 28th (28C3) 2011 |
| March 18, 2012 |
Audio |
Rootkits in your Web application
|
Artur Janc
|
Chaos Communication Congress 28th (28C3) 2011 |
| March 14, 2012 |
Audio |
Effective Denial of Service attacks against web application platforms
|
Alexander Klink
Julian Wälde
|
Chaos Communication Congress 28th (28C3) 2011 |
| March 14, 2012 |
Slides |
Effective Denial of Service attacks against web application platforms
|
Alexander Klink
Julian Wälde
|
Chaos Communication Congress 28th (28C3) 2011 |
| March 14, 2012 |
Video |
Effective Denial of Service attacks against web application platforms
|
Alexander Klink
Julian Wälde
|
Chaos Communication Congress 28th (28C3) 2011 |
| March 13, 2012 |
Audio |
Don't scan, just ask
|
Fabian Mihailowitsch
|
Chaos Communication Congress 28th (28C3) 2011 |
| March 13, 2012 |
Slides |
Don't scan, just ask
|
Fabian Mihailowitsch
|
Chaos Communication Congress 28th (28C3) 2011 |
| March 13, 2012 |
Video |
Don't scan, just ask
|
Fabian Mihailowitsch
|
Chaos Communication Congress 28th (28C3) 2011 |
| February 04, 2012 |
Slides |
New Ways I'm Going to Hack Your Web App
|
Jesse Ou
Rich Lundeen
|
Black Hat Abu Dhabi 2011 |
| February 04, 2012 |
Paper |
New Ways I'm Going to Hack Your Web App
|
Jesse Ou
Rich Lundeen
|
Black Hat Abu Dhabi 2011 |
| January 25, 2012 |
Slides |
Scanning Applications 2.0 - Next Generation Scan, Attacks and Tools
|
Sheeraj Shah
|
Black Hat DC 2008 |
| January 13, 2012 |
Slides |
Web Application Incident Response & Forensics: A Whole New Ball Game!
|
Chuck Willis
Rohyt Belani
|
Black Hat USA 2006 |
| January 07, 2012 |
Slides |
Hacking Intranet Websites from the Outside "JavaScript malware just got a lot more dangerous"
|
Jeremiah Grossman
|
Black Hat USA 2006 |
| January 07, 2012 |
Slides |
Analysis of Web Application Worms and Viruses
|
Billy Hoffman
|
Black Hat USA 2006 |
| January 06, 2012 |
Slides |
MatriXay—When WebApp&Database Security Pen-Test/Audit Is a Joy
|
Xiao Rong
Yuan Fan
|
Black Hat USA 2006 |
| January 04, 2012 |
Slides |
Breaking Crypto Without Keys: Analyzing Data in Web Applications
|
Chris Eng
|
Black Hat USA 2006 |
| January 01, 2012 |
Slides |
Investigating Evil Websites with Monkeyspaw: The Greasemonkey Security Professional's Automated Webthinger
|
Tod Beardsley
|
Black Hat USA 2006 |
| January 01, 2012 |
Slides |
Breaking AJAX Web Applications: Vulns 2.0 in Web 2.0
|
Alex Stamos
Zane Lackey
|
Black Hat Asia 2006 |
| December 31, 2011 |
Slides |
Hacking Intranet Websites from the Outside "JavaScript malware just got a lot more dangerous"
|
Jeremiah Grossman
|
Black Hat Asia 2006 |
| December 31, 2011 |
Slides |
Automatically Detecting Web Application Vulnerabilities by Variable Flow Reconstruction
|
Stefano Zanero
|
Black Hat EU 2005 |
| December 30, 2011 |
Slides |
Defeating Automated Web Assessment Tools
|
Saumil Shah
|
Black Hat EU 2005 |
| December 27, 2011 |
Slides |
Building Zero-Day Self-Defending Web Applications: Enforcing Authoritative Action to Stop Session Attacks
|
Arian Evans
|
Black Hat EU 2005 |
| December 20, 2011 |
Slides |
World Exclusive – Announcing the OWASP Guide To Securing Web Applications and Services 2.0
|
Andrew van der Stock
|
Black Hat USA 2005 |
| December 13, 2011 |
Slides |
The Challenges of Automated Web Application Scanning
|
Jeremiah Grossman
|
Black Hat Windows Security 2004 |
| December 01, 2011 |
Paper |
Evasion and Detection of Web Application Attacks
|
|
Black Hat USA 2004 |
| November 30, 2011 |
Slides |
Web Application Session Strength
|
Michael Shema
|
Black Hat USA 2004 |
| November 30, 2011 |
Slides |
Evasion and Detection of Web Application Attacks
|
|
Black Hat USA 2004 |
| November 24, 2011 |
Slides |
Web Application Security and Release of "WhiteHat Arsenal"
|
Jeremiah Grossman
|
Black Hat Windows Security 2002 |
| November 21, 2011 |
Slides |
Web Application Brute Forcing 101
|
David Endler
Michael Sutton
|
Black Hat USA 2002 |
| November 21, 2011 |
Slides |
Web Application Security
|
Bill Pennington
Dennis Groves
|
Black Hat USA 2002 |
| November 16, 2011 |
Slides |
JD's Toolbox: Fire & Water
|
|
Black Hat USA 2002 |
| November 16, 2011 |
Slides |
Application Testing Through Fault Injection Techniques
|
Greg Hoglund
|
Black Hat USA 2002 |
| November 14, 2011 |
Slides |
Top Ten Web Hacks
|
Saumil Shah
|
Black Hat Asia 2002 |
| November 11, 2011 |
Slides |
Web Hacking Part 1 Hacking Exposed: E-commerce
|
Saumil Shah
|
Black Hat Windows Security 2001 |
| November 11, 2011 |
Slides |
Web Hacking Part 1 & 2
|
Saumil Shah
|
Black Hat Windows Security 2001 |
| November 08, 2011 |
Slides |
Breaking In Through The Front Door
|
Shaun Clowes
|
Black Hat Asia 2001 |
| November 08, 2011 |
Slides |
Web Hacking
|
Saumil Shah
|
Black Hat Asia 2001 |
| November 08, 2011 |
Slides |
Remote Web Application Disassembly with ODBC Error Messages
|
David Litchfield
|
Black Hat Asia 2001 |
| November 08, 2011 |
Paper |
Remote Web Application Disassembly with ODBC Error Messages
|
David Litchfield
|
Black Hat Asia 2001 |
| November 07, 2011 |
Slides |
Web Assessment Tools
|
|
Black Hat Asia 2001 |
| October 31, 2011 |
Slides |
Web Vulnerability & SQL Injection Countermeasures
|
Tim Mullen
|
Black Hat EU 2001 |
| October 31, 2011 |
Slides |
One-Way SQL Hacking
|
Saumil Shah
|
Black Hat EU 2001 |
| October 31, 2011 |
Slides |
Web Application Security
|
Jeremiah Grossman
|
Black Hat EU 2001 |
| October 20, 2011 |
Slides |
HTTP: Advanced Assessment Techniques
|
Saumil Shah
|
Black Hat Windows Security 2003 |
| October 19, 2011 |
Slides |
Web Application Security
|
Bill Pennington
Jeremiah Grossman
|
Black Hat Windows Security 2003 |
| October 11, 2011 |
Slides |
HTTP Fingerprinting and Advanced Assessment Techniques
|
Saumil Shah
|
Black Hat USA 2003 |
| October 05, 2011 |
Slides |
HTTP Fingerprinting and Advanced Assessment Techniques
|
Saumil Shah
|
Black Hat Federal 2003 |
| October 02, 2011 |
Slides |
The Challenges of Automated Web Application Scanning
|
Jeremiah Grossman
|
Black Hat Federal 2003 |
| October 02, 2011 |
Slides |
HTTP Fingerprinting and Advanced Assessment Techniques
|
Saumil Shah
|
Black Hat Asia 2003 |
| September 24, 2011 |
Slides |
BlindElephant: WebApp Fingerprinting and Vulnerability Inferencing
|
Patrick Thomas
|
Black Hat USA 2010 |
| September 13, 2011 |
Paper |
Constricting the Web: Offensive Python for Web Hackers
|
Marcin Wielgoszewski
Nathan Hamiel
|
Black Hat USA 2010 |
| September 13, 2011 |
Slides |
Constricting the Web: Offensive Python for Web Hackers
|
Marcin Wielgoszewski
Nathan Hamiel
|
Black Hat USA 2010 |
| September 08, 2011 |
Paper |
JavaSnoop: How to hack anything written in Java
|
Arshan Dabirsiaghi
|
Black Hat USA 2010 |
| September 08, 2011 |
Slides |
JavaSnoop: How to hack anything written in Java
|
Arshan Dabirsiaghi
|
Black Hat USA 2010 |
| August 19, 2011 |
Video |
CARAT - Configuration And Risk Assessment Toolkit, Metasploit within the Enterprise
|
Max Moser
Philipp Schrödel
|
Hashdays 2010 |
| August 08, 2011 |
Slides |
Smashing Web Apps: Applying Fuzzing to Web Applications and Web Services
|
Michael Sutton
|
Black Hat DC 2007 |
| July 22, 2011 |
Paper |
ScarabMon - Automating Web Application Penetration Tests
|
Jonathan Wilkins
|
Black Hat EU 2007 |
| July 19, 2011 |
Paper |
Kicking Down the Cross Domain Door (One XSS at a Time)
|
Billy Rios
Raghav Dube
|
Black Hat EU 2007 |
| July 19, 2011 |
Slides |
Kicking Down the Cross Domain Door (One XSS at a Time)
|
Billy Rios
Raghav Dube
|
Black Hat EU 2007 |
| July 13, 2011 |
Paper |
Make My Day – Just Run a Web Scanner: Countering The Faults of Typical Web Scanners Through Byte-code Injection
|
Toshinari Kureha
|
Black Hat EU 2007 |
| July 13, 2011 |
Slides |
Make My Day – Just Run a Web Scanner: Countering The Faults of Typical Web Scanners Through Byte-code Injection
|
Toshinari Kureha
|
Black Hat EU 2007 |
| May 10, 2011 |
Paper |
A Dynamic Technique for Enhancing the Security and Privacy of Web Applications
|
Ariel Waissbein
Ezequiel D. Gutesman
|
Black Hat USA 2007 |
| May 10, 2011 |
Slides |
A Dynamic Technique for Enhancing the Security and Privacy of Web Applications
|
Ariel Waissbein
Ezequiel D. Gutesman
|
Black Hat USA 2007 |
| April 16, 2011 |
Slides |
Extrusion and Web Hacking
|
Laurent Oudot
|
Black Hat Abu Dhabi 2010 |
| April 16, 2011 |
Paper |
Extrusion and Web Hacking
|
Laurent Oudot
|
Black Hat Abu Dhabi 2010 |
| April 16, 2011 |
Paper |
Attacking with HTML5
|
Lavakumar Kuppan
|
Black Hat Abu Dhabi 2010 |
| April 16, 2011 |
Slides |
Attacking with HTML5
|
Lavakumar Kuppan
|
Black Hat Abu Dhabi 2010 |
| March 31, 2011 |
Audio |
Web Application Fingerprinting with Static Files
|
Patrick Thomas
|
DEFCON 18 |
| March 31, 2011 |
Slides |
Web Application Fingerprinting with Static Files
|
Patrick Thomas
|
DEFCON 18 |
| March 31, 2011 |
Video |
Web Application Fingerprinting with Static Files
|
Patrick Thomas
|
DEFCON 18 |
| March 03, 2011 |
Paper |
Hacking .NET Applications at Runtime: A Dynamic Attack
|
Jon McCoy
|
DEFCON 18 |
| March 03, 2011 |
Slides |
Hacking .NET Applications at Runtime: A Dynamic Attack
|
Jon McCoy
|
DEFCON 18 |
| March 02, 2011 |
Audio |
Hacking .NET Applications at Runtime: A Dynamic Attack
|
Jon McCoy
|
DEFCON 18 |
| March 02, 2011 |
Video |
Hacking .NET Applications at Runtime: A Dynamic Attack
|
Jon McCoy
|
DEFCON 18 |
| February 20, 2011 |
Audio |
Black Ops Of Fundamental Defense: Web Edition
|
Dan Kaminsky
|
DEFCON 18 |
| February 20, 2011 |
Video |
Black Ops Of Fundamental Defense: Web Edition
|
Dan Kaminsky
|
DEFCON 18 |
| February 14, 2011 |
Video |
Ripping Media Off Of the Wire
|
|
DEFCON 18 |
| February 14, 2011 |
Audio |
Ripping Media Off Of the Wire
|
|
DEFCON 18 |
| February 14, 2011 |
Slides |
Ripping Media Off Of the Wire
|
|
DEFCON 18 |
| February 10, 2011 |
Slides |
Constricting the Web: Offensive Python for Web Hackers
|
Marcin Wielgoszewski
Nathan Hamiel
|
DEFCON 18 |
| February 10, 2011 |
Video |
Constricting the Web: Offensive Python for Web Hackers
|
Marcin Wielgoszewski
Nathan Hamiel
|
DEFCON 18 |
| January 26, 2011 |
Slides |
Google Toolbar: The NARC Within
|
Jeff Bryner
|
DEFCON 18 |
| January 26, 2011 |
Audio |
Google Toolbar: The NARC Within
|
Jeff Bryner
|
DEFCON 18 |
| January 26, 2011 |
Video |
Google Toolbar: The NARC Within
|
Jeff Bryner
|
DEFCON 18 |
| January 12, 2011 |
Slides |
CARAT - Configuration And Risk Assessment Toolkit, Metasploit within the Enterprise
|
Max Moser
Philipp Schrödel
|
Hashdays 2010 |
| January 11, 2011 |
Paper |
Connection String Parameter Attacks
|
Chema Alonso
Jose Palazon
|
DEFCON 18 |
| January 11, 2011 |
Slides |
Connection String Parameter Attacks
|
Chema Alonso
Jose Palazon
|
DEFCON 18 |
| January 11, 2011 |
Video |
Connection String Parameter Attacks
|
Chema Alonso
Jose Palazon
|
DEFCON 18 |
| January 11, 2011 |
Video |
Connection String Parameter Attacks
|
Chema Alonso
Jose Palazon
|
DEFCON 18 |
| December 25, 2010 |
Slides |
Web Scanners FOR THE WIN...
|
Louis Nyffenegger
|
Ruxcon 2010 |
| December 12, 2010 |
Video |
BLINDELEPHANT: Web Application Fingerprinting with Static Files
|
Patrick Thomas
|
SecTor 2010 |
| December 12, 2010 |
Slides |
BLINDELEPHANT: Web Application Fingerprinting with Static Files
|
Patrick Thomas
|
SecTor 2010 |
| December 06, 2010 |
Video |
400 Apps in 40 Days
|
Nish Bhalla
Sahba Kazerooni
|
SecTor 2010 |
| December 06, 2010 |
Slides |
400 Apps in 40 Days
|
Nish Bhalla
Sahba Kazerooni
|
SecTor 2010 |
| December 04, 2010 |
Video |
Web Application Payloads
|
Andrés Pablo Riancho
|
SecTor 2010 |
| December 03, 2010 |
Slides |
Web Application Payloads
|
Andrés Pablo Riancho
|
SecTor 2010 |
| December 01, 2010 |
Video |
Into the Rabbit Hole
|
Rafal Los
|
SecTor 2010 |
| December 01, 2010 |
Slides |
Into the Rabbit Hole
|
Rafal Los
|
SecTor 2010 |
| November 14, 2010 |
Video |
Something New Something Web Something Not Security
|
|
PhreakNIC 13 |
| November 01, 2010 |
Video |
Covert Crawling
|
Billy Hoffman
|
LayerOne 2006 |
| November 01, 2010 |
Slides |
Covert Crawling
|
Billy Hoffman
|
LayerOne 2006 |
| October 20, 2010 |
Slides |
W.E.B. 2010 Web. Exploits. Browsers.
|
Saumil Shah
|
Hack In The Box 2010 Malaysia |
| October 18, 2010 |
Slides |
Milking a horse or executing remote code in modern Java frameworks
|
Meder Kydyraliev
|
Hack In The Box 2010 Malaysia |
| October 02, 2010 |
Slides |
Improving the Stealthiness of Web Hacking
|
Laurent Oudot
|
Hack In The Box 2010 Dubai |
| August 05, 2010 |
Slides |
REST for the Wicked
|
Bryan Sullivan
|
Black Hat USA 2008 |
| August 05, 2010 |
Audio |
REST for the Wicked
|
Bryan Sullivan
|
Black Hat USA 2008 |
| August 05, 2010 |
Video |
REST for the Wicked
|
Bryan Sullivan
|
Black Hat USA 2008 |
| August 04, 2010 |
Audio |
Concurrency Attacks in Web Applications
|
Scott Stender
|
Black Hat USA 2008 |
| August 04, 2010 |
Video |
Concurrency Attacks in Web Applications
|
Scott Stender
|
Black Hat USA 2008 |
| July 20, 2010 |
Audio |
Pushing the Camel through the Eye of a Needle
|
|
Black Hat USA 2008 |
| July 20, 2010 |
Slides |
Pushing the Camel through the Eye of a Needle
|
|
Black Hat USA 2008 |
| July 20, 2010 |
Video |
Pushing the Camel through the Eye of a Needle
|
|
Black Hat USA 2008 |
| July 04, 2010 |
Video |
Encoded, Layered, and Trancoded Syntax Attacks: Threading the Needle past Web Application Security Controls
|
Arian Evans
|
Black Hat USA 2008 |
| July 04, 2010 |
Audio |
Encoded, Layered, and Trancoded Syntax Attacks: Threading the Needle past Web Application Security Controls
|
Arian Evans
|
Black Hat USA 2008 |
| June 18, 2010 |
Slides |
Practical Crypto Attacks Against Web Applications
|
Thai Duong
Juliano Rizzo
|
Black Hat EU 2010 |
| June 17, 2010 |
Paper |
Practical Crypto Attacks Against Web Applications
|
Thai Duong
Juliano Rizzo
|
Black Hat EU 2010 |
| June 05, 2010 |
Slides |
The Fine Art of Hari Kari (.JS), And Other Approaches For The Strange Reality Of Web Defense
|
Dan Kaminsky
|
Source Conference Boston 2010 |
| May 31, 2010 |
Slides |
Attacking WebOS
|
Chris Clark
Townsend Ladd Harris
|
Source Conference Boston 2010 |
| May 14, 2010 |
Slides |
Beware of Serialized GUI Objects Bearing Data
|
David Byrne
Rohini Sulatycki
|
Black Hat DC 2010 |
| May 04, 2010 |
Audio |
Metasploit Goes Web
|
Efrain Torres
|
DEFCON 17 |
| May 04, 2010 |
Slides |
Metasploit Goes Web
|
Efrain Torres
|
DEFCON 17 |
| May 04, 2010 |
Video |
Metasploit Goes Web
|
Efrain Torres
|
DEFCON 17 |
| April 27, 2010 |
Video |
Screen Scraper Tricks: Extracting Data from Difficult Websites
|
Michael Schrenk
|
DEFCON 17 |
| April 27, 2010 |
Slides |
Screen Scraper Tricks: Extracting Data from Difficult Websites
|
Michael Schrenk
|
DEFCON 17 |
| April 27, 2010 |
Audio |
Screen Scraper Tricks: Extracting Data from Difficult Websites
|
Michael Schrenk
|
DEFCON 17 |
| April 24, 2010 |
Audio |
The security risks of Web 2.0
|
David Rook
|
DEFCON 17 |
| April 24, 2010 |
Slides |
The security risks of Web 2.0
|
David Rook
|
DEFCON 17 |
| April 24, 2010 |
Video |
The security risks of Web 2.0
|
David Rook
|
DEFCON 17 |
| April 13, 2010 |
Video |
Weaponizing the Web: New Attacks on User-generated Content
|
Shawn Moyer
Nathan Hamiel
|
DEFCON 17 |
| April 13, 2010 |
Audio |
Weaponizing the Web: New Attacks on User-generated Content
|
Shawn Moyer
Nathan Hamiel
|
DEFCON 17 |
| February 26, 2010 |
Video |
The Middler 2.0: It's Not Just for Web Apps Anymore
|
Jay Beale
Justin Searle
|
DEFCON 17 |
| February 26, 2010 |
Slides |
The Middler 2.0: It's Not Just for Web Apps Anymore
|
Jay Beale
Justin Searle
|
DEFCON 17 |
| February 26, 2010 |
Audio |
The Middler 2.0: It's Not Just for Web Apps Anymore
|
Jay Beale
Justin Searle
|
DEFCON 17 |
| February 26, 2010 |
Video |
CSRF: Yeah, It Still Works
|
Mike Bailey
Russ McRee
|
DEFCON 17 |
| February 26, 2010 |
Audio |
CSRF: Yeah, It Still Works
|
Mike Bailey
Russ McRee
|
DEFCON 17 |
| February 26, 2010 |
Slides |
CSRF: Yeah, It Still Works
|
Mike Bailey
Russ McRee
|
DEFCON 17 |
| February 24, 2010 |
Video |
Session Donation
|
Alek Amrani
|
DEFCON 17 |
| February 24, 2010 |
Audio |
Session Donation
|
Alek Amrani
|
DEFCON 17 |
| February 24, 2010 |
Slides |
Session Donation
|
Alek Amrani
|
DEFCON 17 |
| December 20, 2009 |
Paper |
Improving Application Security with Data Flow Assertions
|
|
|
| December 19, 2009 |
Audio |
Hacking the EULA: Reverse Benchmarking Web Application Security Scanners
|
Tom Stracener
Marce Luck
|
DEFCON 15 |
| December 17, 2009 |
Audio |
The Executable Image Exploit
|
Michael Schrenk
|
DEFCON 15 |
| December 16, 2009 |
Audio |
Biting the Hand that Feeds You - Storing and Serving Malicous Content From Well Known Web Servers
|
Billy Rios
Nathan McFeters
|
DEFCON 15 |
| December 14, 2009 |
Audio |
Greater than 1: Defeating "strong" Authentication in Web Applications
|
Brendan O'Connor
|
DEFCON 15 |
| December 11, 2009 |
Audio |
Comparing Application Security Tools
|
Edward Lee
|
DEFCON 15 |
| December 11, 2009 |
Audio |
Black Ops 2007: Design Reviewing The Web
|
Dan Kaminsky
|
DEFCON 15 |
| November 29, 2009 |
Audio |
Intranet Invasion With Anti-DNS Pinning
|
David Byrne
|
DEFCON 15 |
| November 23, 2009 |
Audio |
Web Privacy and Flash Local Shared Objects
|
Clinton Wong
|
DEFCON 16 |
| November 05, 2009 |
Audio |
Hacking E.S.P.
|
Joe Cicero
Michael Vieau
|
DEFCON 16 |
| November 04, 2009 |
Audio |
Building a Real Session Layer
|
|
DEFCON 16 |
| November 04, 2009 |
Audio |
Grendel-Scan: A new web application scanning tool
|
David Byrne
Eric Duprey
|
DEFCON 16 |
| October 28, 2009 |
Slides |
Beyond Attack Patterns - Positive Security Models with ModSecurity
|
Christian Bockermann
|
Digital Security Forum - 2nd |
| October 18, 2009 |
Slides |
Exploiting Native Client
|
Ben Hawkes
|
HAR 2009 |
| October 18, 2009 |
Video |
Exploiting Native Client
|
Ben Hawkes
|
HAR 2009 |
| October 17, 2009 |
Video |
WebAppInSec : 101 threats
|
Jacco van Tuijl
|
HAR 2009 |
| September 23, 2009 |
Slides |
Defensive Rewriting: A New Take on XSS/XSRF/Redirect-Phishing Defense
|
Bryan Sullivan
|
Black Hat USA 2009 |
| September 23, 2009 |
Paper |
Defensive Rewriting: A New Take on XSS/XSRF/Redirect-Phishing Defense
|
Bryan Sullivan
|
Black Hat USA 2009 |
| September 09, 2009 |
Slides |
Veiled: A Browser-based Darknet
|
Billy Hoffman
Matt Wood
|
Black Hat USA 2009 |
| September 09, 2009 |
Paper |
Weaponizing the Web: More Attacks on User-Generated Content
|
Shawn Moyer
Nathan Hamiel
|
Black Hat USA 2009 |
| September 09, 2009 |
Slides |
Weaponizing the Web: More Attacks on User-Generated Content
|
Shawn Moyer
Nathan Hamiel
|
Black Hat USA 2009 |
| September 08, 2009 |
Slides |
Mo' Money Mo' Problems: Making A LOT More Money on the Web the Black Hat Way
|
Jeremiah Grossman
Trey Ford
|
Black Hat USA 2009 |
| July 30, 2009 |
Video |
Hacking the EULA: Reverse Benchmarking Web Application Security Scanners
|
Tom Stracener
Marce Luck
|
DEFCON 15 |
| July 30, 2009 |
Slides |
Hacking the EULA: Reverse Benchmarking Web Application Security Scanners
|
Tom Stracener
Marce Luck
|
DEFCON 15 |
| July 25, 2009 |
Video |
The Executable Image Exploit
|
Michael Schrenk
|
DEFCON 15 |
| July 25, 2009 |
Slides |
The Executable Image Exploit
|
Michael Schrenk
|
DEFCON 15 |
| July 24, 2009 |
Video |
Biting the Hand that Feeds You - Storing and Serving Malicous Content From Well Known Web Servers
|
Billy Rios
Nathan McFeters
|
DEFCON 15 |
| July 24, 2009 |
Slides |
Biting the Hand that Feeds You - Storing and Serving Malicous Content From Well Known Web Servers
|
Billy Rios
Nathan McFeters
|
DEFCON 15 |
| July 24, 2009 |
Paper |
Biting the Hand that Feeds You - Storing and Serving Malicous Content From Well Known Web Servers
|
Billy Rios
Nathan McFeters
|
DEFCON 15 |
| July 11, 2009 |
Slides |
Secure Programming with the Zend Framework
|
Stefan Esser
|
|
| July 11, 2009 |
Slides |
PHP Security Crash Course for beginners: Part VI + VII - PHP Code Inclusion and PHP Code Evaluation
|
Stefan Esser
|
|
| July 11, 2009 |
Slides |
PHP Security Crash Course for beginners: Part V - Session Management Security
|
Stefan Esser
|
|
| July 11, 2009 |
Slides |
PHP Security Crash Course for beginners: Part IV - SQL Security
|
Stefan Esser
|
|
| July 11, 2009 |
Slides |
PHP Security Crash Course for beginners: Part III -CSRF
|
Stefan Esser
|
|
| July 11, 2009 |
Slides |
PHP Security Crash Course for beginners: Part II - XSS
|
Stefan Esser
|
|
| July 11, 2009 |
Slides |
PHP Security Crash Course for beginners: Part I - Introduction
|
Stefan Esser
|
|
| July 11, 2009 |
Paper |
Detecting Remote File Inclusion attack
|
Or Katz
|
|
| July 02, 2009 |
Video |
Greater than 1: Defeating "strong" Authentication in Web Applications
|
Brendan O'Connor
|
DEFCON 15 |
| July 02, 2009 |
Slides |
Greater than 1: Defeating "strong" Authentication in Web Applications
|
Brendan O'Connor
|
DEFCON 15 |
| June 25, 2009 |
Slides |
I thought you were my friend Malicious markup, browser issues and other obscurities
|
Mario Heiderich
|
Confidence 2009 Krakow |
| June 20, 2009 |
Paper |
A Gap Analysis of Application Security in Struts2/WebWork
|
Arshan Dabirsiaghi
|
|
| June 20, 2009 |
Slides |
Application Injections - Exploiting SQL, XSS & XPATH
|
Shreeraj Shah
|
Confidence 2009 Krakow |
| June 18, 2009 |
Video |
Comparing Application Security Tools
|
Edward Lee
|
DEFCON 15 |
| June 18, 2009 |
Slides |
Comparing Application Security Tools
|
Edward Lee
|
DEFCON 15 |
| June 17, 2009 |
Video |
Black Ops 2007: Design Reviewing The Web
|
Dan Kaminsky
|
DEFCON 15 |
| June 17, 2009 |
Slides |
Black Ops 2007: Design Reviewing The Web
|
Dan Kaminsky
|
DEFCON 15 |
| May 31, 2009 |
Video |
Intranet Invasion With Anti-DNS Pinning
|
David Byrne
|
DEFCON 15 |
| May 31, 2009 |
Paper |
Intranet Invasion With Anti-DNS Pinning
|
David Byrne
|
DEFCON 15 |
| April 15, 2009 |
Slides |
Get Rich or Die Trying - "Making Money on the Web the Black Hat Way"
|
Jeremiah Grossman
|
Source Conference Boston 2009 |
| April 12, 2009 |
Video |
Web Privacy and Flash Local Shared Objects
|
Clinton Wong
|
DEFCON 16 |
| April 12, 2009 |
Slides |
Web Privacy and Flash Local Shared Objects
|
Clinton Wong
|
DEFCON 16 |
| March 26, 2009 |
Video |
Hacking E.S.P.
|
Joe Cicero
Michael Vieau
|
DEFCON 16 |
| March 25, 2009 |
Slides |
Hacking E.S.P.
|
Joe Cicero
Michael Vieau
|
DEFCON 16 |
| March 15, 2009 |
Video |
Building a Real Session Layer
|
|
DEFCON 16 |
| March 15, 2009 |
Slides |
Building a Real Session Layer
|
|
DEFCON 16 |
| March 15, 2009 |
Video |
Grendel-Scan: A new web application scanning tool
|
David Byrne
Eric Duprey
|
DEFCON 16 |
| March 15, 2009 |
Slides |
Grendel-Scan: A new web application scanning tool
|
David Byrne
|
DEFCON 16 |
| March 13, 2009 |
Video |
Vulnerability discovery in encrypted closed source PHP applications
|
Stefan Esser
|
Chaos Communication Congress 25th (25C3) 2008 |
| January 22, 2009 |
Slides |
Intelligent Web Fuzzing
|
|
Ruxcon 2008 |
| October 10, 2008 |
Slides |
Security Testing with Selenium
|
Vidar Kongsli
|
|
| July 18, 2008 |
Slides |
Website Vulnerabilities Revealed: What everyone knew, but afraid to believe
|
Jeremiah Grossman
|
|
| July 16, 2008 |
Paper |
Security Testing Applications through Automated Software Tests
|
|
|
| July 16, 2008 |
Paper |
A Modular Approach to Data Validation in Web Applications
|
|
|
| July 16, 2008 |
Paper |
Cookie Path Best Practice
|
|
|
| July 16, 2008 |
Paper |
Application Level DoS Attacks
|
|
|
| July 06, 2008 |
Slides |
Path X - Explosive Security Testing Tools with XPath
|
|
Shmoocon 2008 |
| June 05, 2008 |
Paper |
Bypassing URL Authentication and Authorization with HTTP Verb Tampering
|
Arshan Dabirsiaghi
|
|
| December 31, 2007 |
Paper |
Authentication and Session Management on the Web
|
Paul Johnston
|
|
| December 30, 2007 |
Paper |
Web Based Session Management
|
Gunter Ollmann
|
|