Down the Security Rabbithole Podcast (DtSR)

DtR Episode 25 - Guests: Jim Manico, David Litchfield - From Black Hat 2012 with SQLi


Listen Later

Send the hosts a message - try it now!

Syhopsis

When I caught up with these two gentlemen in Amsterdam over the week of Black Hat 2012, I knew we wouldn't run out of things to talk about!  We ended up chatting for quite some time, and I think you'll find this conversation interesting from hearing of David's recent work with Oracle, and Jim's perspective on "the fix"... I kept the conversation going and am probably at last partially responsible for how long this podcast ended up being.  It's well worth the time, in my opinion, as we cover the following topics:

  • Attacking Oracle (David's talk had to be shelved, but he talks about ways to attack Oracle via putting a string into a numeric query - by manipulating the meta-environment)
  • Jim & David talk about how to do sane SQL Injection protection (bind everything!)
  • David talks about some contrived ways of hacking Oracle databases, that are 'outside the business logic' and explains why validation is still important
  • Jim brings up structural validation of inputs (useful white-listing)
  • David brings up that his exploits from 2007 are STILL working in 2012 - terrifying
  • "Parameterize it, or jeopardize it" - Jim's campaign to rid the world of SQL Injection
  • David talks about unconventional database forensics that identify attacks via weblogs
  • Vendors have upped their game to protect applications, developers are still writing bad code
  • Jim Manico "We are entering the golden age of hackers" ... does this mean better security?!
  • David discusses how if MS had stopped development of NEW features, WinNT4 would be 'secure' by now... but innovation & features will continue to drive forward - security suffers
  • Jim asks "does the [development] framework of the future, consider security as a built-in?"

Guests

  • Jim Manico - One of the people who holds OWASP together, Jim is an enthusiastic espouser of the Web App Security word.  You can find him providing training, practical advice, and code knowledge all over the place, particularly for the OWASP organization.
  • David Litchfield - David has been taking Oracle to task over their claims of database security for years, and continues to be a driving force behind penetration testing, database forensics, and all things Oracle security.

Support the show

>>> Please consider clicking the link above to support the show!
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
YouTube home: https://youtube.com/playlist?list=PLyo0dkKRvfVtWXjRxNISrhme1MgBj3C2U&si=scHDiTuLXSEQ9qHq
LinkedIn Page: https://www.linkedin.com/company/down-the-security-rabbithole-podcast/
X/Twitter: https://twitter.com/dtsr_podcast

...more
View all episodesView all episodes
Download on the App Store

Down the Security Rabbithole Podcast (DtSR)By Rafal (Wh1t3Rabbit) Los

  • 4.3
  • 4.3
  • 4.3
  • 4.3
  • 4.3

4.3

96 ratings


More shows like Down the Security Rabbithole Podcast (DtSR)

View all
Security Now (Audio) by TWiT

Security Now (Audio)

1,966 Listeners

Risky Business by Patrick Gray

Risky Business

360 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

628 Listeners

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec by Jerry Bell and Andrew Kalat

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec

367 Listeners

Hacked by Hacked

Hacked

179 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,015 Listeners

Smashing Security by Graham Cluley & Carole Theriault

Smashing Security

314 Listeners

Click Here by Recorded Future News

Click Here

392 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

7,853 Listeners

CISO Series Podcast by David Spark, Mike Johnson, and Andy Ellis

CISO Series Podcast

187 Listeners

Hacking Humans by N2K Networks

Hacking Humans

314 Listeners

Defense in Depth by David Spark, Steve Zalewski, Geoff Belknap

Defense in Depth

78 Listeners

Cyber Security Headlines by CISO Series

Cyber Security Headlines

117 Listeners

Risky Bulletin by risky.biz

Risky Bulletin

33 Listeners

Hacker And The Fed by Chris Tarbell & Hector Monsegur

Hacker And The Fed

158 Listeners