DtR Episode 25 - Guests: Jim Manico, David Litchfield - From Black Hat 2012 with SQLi episode artwork

EPISODE · Oct 22, 2012 · 50 MIN

DtR Episode 25 - Guests: Jim Manico, David Litchfield - From Black Hat 2012 with SQLi

from Down the Security Rabbithole Podcast (DtSR)

Syhopsis When I caught up with these two gentlemen in Amsterdam over the week of Black Hat 2012, I knew we wouldn't run out of things to talk about!  We ended up chatting for quite some time, and I think you'll find this conversation interesting from hearing of David's recent work with Oracle, and Jim's perspective on "the fix"... I kept the conversation going and am probably at last partially responsible for how long this podcast ended up being.  It's well worth the time, in my opinion, as we cover the following topics:Attacking Oracle (David's talk had to be shelved, but he talks about ways to attack Oracle via putting a string into a numeric query - by manipulating the meta-environment)Jim & David talk about how to do sane SQL Injection protection (bind everything!)David talks about some contrived ways of hacking Oracle databases, that are 'outside the business logic' and explains why validation is still importantJim brings up structural validation of inputs (useful white-listing)David brings up that his exploits from 2007 are STILL working in 2012 - terrifying"Parameterize it, or jeopardize it" - Jim's campaign to rid the world of SQL InjectionDavid talks about unconventional database forensics that identify attacks via weblogsVendors have upped their game to protect applications, developers are still writing bad codeJim Manico "We are entering the golden age of hackers" ... does this mean better security?!David discusses how if MS had stopped development of NEW features, WinNT4 would be 'secure' by now... but innovation & features will continue to drive forward - security suffersJim asks "does the [development] framework of the future, consider security as a built-in?"GuestsJim Manico - One of the people who holds OWASP together, Jim is an enthusiastic espouser of the Web App Security word.  You can find him providing training, practical advice, and code knowledge all over the place, particularly for the OWASP organization.David Litchfield - David has been taking Oracle to task over their claims of database security for years, and continues to be a driving force behind penetration testing, database forensics, and all things Oracle security.Have something to say? Let's hear it.Support the show>>> Please consider clicking the link above to support the show!-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=YouTube home: https://youtube.com/playlist?list=PLyo0dkKRvfVtWXjRxNISrhme1MgBj3C2U&si=scHDiTuLXSEQ9qHqLinkedIn Page: https://www.linkedin.com/company/down-the-security-rabbithole-podcast/X/Twitter: https://twitter.com/dtsr_podcast

Episode metadata supplied by the publisher feed · Published Oct 22, 2012

Embed this episode

Syhopsis When I caught up with these two gentlemen in Amsterdam over the week of Black Hat 2012, I knew we wouldn't run out of things to talk about! We ended up chatting for quite some time, and I think you'll find this conversation interesting from hearing of David's recent work with Oracle, and Jim's perspective on "the fix"... I kept the conversation going and am probably at last partially responsible for how long this podcast ended up being. It's well worth the time, in my op...

Distinct summary based on available episode metadata or transcript content.

NOW PLAYING

DtR Episode 25 - Guests: Jim Manico, David Litchfield - From Black Hat 2012 with SQLi

0:00 50:15

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of Down the Security Rabbithole Podcast (DtSR)?

This episode is 50 minutes long.

When was this Down the Security Rabbithole Podcast (DtSR) episode published?

This episode was published on October 22, 2012.

Can I download this Down the Security Rabbithole Podcast (DtSR) episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!