Showing posts with label Web Application Security. Show all posts
Showing posts with label Web Application Security. Show all posts

Sunday, July 31, 2011

OWASP Top 10 Quiz

We had recently developed a quiz to help an organization test their developer's knowledge of OWASP top 10. I thought it would be a good idea to make it public and let other organization use it for their development teams as well. This is a very basic quiz but I do plan to add different levels and more questions to it and bring randomness in the questions as well.

I would greatly appreciate any feedback or suggestions that others may have.

http://owasp.myappsecurity.com/2011/07/12/quiz/

Wednesday, April 13, 2011

OWASP threat modeling project

We are starting an OWASP threat modeling project to standardize a threat modeling approach which can be used by various companies. During the OWASP portugal summit I had a very meaningful and positive discussion on this topic and got support from a lot of people in the community. You can find out the results of the discussion at the OWASP Threat Modeling project page

If you would like to join the project, please join the mailing list at


Here are some of the topics to be taken up in the first meeting (most probably to be scheduled for next week)
  1. High level project roadmap with milestones.
  2. Call for participants
  3. Review existing resources within OWASP to align with threat modeling project.
  4. Come up with a threat modeling methodology
  5. Publish the first draft

Thursday, May 06, 2010

Free Hands on Workshop on Web Application Security in New York City

Ever wondered how a hacker hacks all these credit cards? Do you think hacking a website is difficult? What are the skills required to hack a website?

ISSA NY Metro chapter is organizing a 3 hour workshop on web application security. This session will show you how easy it is to steal credit card numbers, SSN, etc by doing a SQL injection attack or how you can steal passwords, hijack a session using Cross Site Scripting (XSS). This session will not only make you think like a hacker but also make you find and exploit vulnerabilities in a live web application that closely resembles those containing your personal information, credit card numbers and even medical history.Attendance is free for ISSA members and $35 for non members. This is a hands on session so please bring a laptop to this event to fully benefit from the material that will be presented. If you do not have a laptop, you should still attend and share with another member, or follow along on the big screen. PLease do not send RSVP, instead register at the link below.

Only 30 seats left


Event Type : Workshop / Hands on Training
Date & Time : May 27, 2010 2pm - 5pm
Price : Free for members, 35 for non-members

Location :

PriceWaterHouseCoopers
300 Madison Ave (Corner 42 Street)
New York, NY 10017


Registration Link - http://guest.cvent.com/EVENTS/Info/Summary.aspx?e=f1707482-d496-4011-b4cb-0e9e212012d7
Event Link - http://www.nymissa.org/2010/04/23/tricks-of-the-trade-web-application-security-2/

Monday, June 04, 2007

Reflection on Saumil Shah


This week on reflection we have Saumil Shah from net-square Solutions. Saumil has been involed in webappsec community for a long time and is a regular presenter at Blackhat. He focuses on researching vulnerabilities with various e-commerce and web based application systems, system architecture for Net-Square's tools and products, and developing short term training programmes. He specializes in ethical hacking and security architecture. In his reflection, Saumil shares with us how he got involed in webappsec. In his own words

“My original interest in security has always been Unix hacking and reverse engineering. In 1998, when I joined Ernst & Young as a penetration testing specialist, we used to have a field day with systems wide open on the Internet. NetBIOS and SunRPC made our day. Not to mention a slew of other services like open database ports, terminal ports, and more. By the end of 1999, the only ports we could find open on the Internet were 80 and 443. Not to be outdone, I ended up finding out ways to compromise systems, this time using HTTP and the application behind it.

Leaving apart the whole idiotic debate on hacking vs. cracking, I shall say that I truly started hacking at the age of 11. My first few "hacks" were to spot programming errors in home computer magazines, for the ZX Spectrum and the BBC Micro, fixing them while keying in long listings in BASIC, and enjoying the games until I had to unplug the power. The only storage medium was cassette tape back in 1984.”



Based out of Ahmedabad, India, Saumil is only 33 years old and is a co-author of "Web Hacking: Attacks and Defense" (Addison Wesley, 2002) and is the author of "The Anti-Virus Book" (Tata McGraw-Hill, 1996). He has served as a technical editor for "Hacking Exposed 2nd Ed", and has contributed to "Know your Enemy - the Honeynet Project" book. Saumil has also presented at Blackhat, CNET eDevCon, hack.lu, EUSecWest, and many more. Below are a list of his contributions to the webappsec community.

Books:-

Web Hacking - Attacks and Defense
http://www.awprofessional.com/bookstore/product.asp?isbn=0201761769&rl=1

The Anti Virus Book
http://saumil.net/antivirus/contents.html


Articles:-

Saumil did a monthly column for two years on C-NET Builder.com, titled ”Security Issues”, along with Chris Prosise.
http://builder.cnet.com/

One Way Web Hacking
http://net-square.com/papers/one_way

An Introduction to HTTP fingerprinting
http://net-square.com/httprint/httprint_paper.html


Tools written by him:-

httprint - Advanced HTTP Fingerprinting
http://net-square.com/httprint/


Contributions:-

One of the very early members of The Honeynet Project in 2000.


Presentations:-

Web Hacking
http://www.blackhat.com/html/win-usa-01/win-usa-01-speakers.html

Adware/Spyware
http://www.blackhat.com/html/bh-japan-05/bh-jp-05-en-speakers.html

The Exploit Laboratory: Analyzing Vulnerabilities and Writing Exploits
(Black Hat Europe 2006 Briefings and Training, Black Hat USA Training 2006)
http://www.blackhat.com/html/bh-usa-06/train-bh-us-06-ss-el.html

Defeating Automated Web Assessment Tools
http://www.blackhat.com/html/bh-usa-04/bh-usa-04-speakers.html


HTTP Fingerprinting and Advanced Assessment Techniques – (BH Europe 2004, BH Asia 2003, BH Federal 2003, BH Windows 2004)
http://www.blackhat.com/html/bh-europe-04/bh-europe-04-speakers.html


HTTP: Advanced Assessment Techniques
http://www.blackhat.com/html/win-usa-03/win-usa-03-speakers.html#Saumil%20Udayan%20Shah


Top Ten Web Attacks
http://www.blackhat.com/html/bh-asia-02/bh-asia-02-speakers.html

One-Way SQL Hacking: Futility of Firewalls in Web Hacking
http://www.blackhat.com/html/bh-europe-01/bh-europe-01-speakers.html#Marc%20Witteman


Writing Metasploit Plugins - From Vulnerability to Exploit
http://conference.hackinthebox.org/hitbsecconf2006kl/?page_id=81


CNET eDevCon 2000: "Hacking Exposed: Ecommerce - Live!


Company working for:-

Net-Square - Founder and CEO
http://net-square.com/


Companies worked for:-

Ernst & Young, Foundstone


Email:-

saumil__at__net-square_dot_com


Website:-
http://saumil.net/


Education:-

M.S. Computer Science, Purdue University, USA - graduated in 1998
B.E. Computer Engineering, Gujarat University, India - graduated in 1995


Saumil has also been doing pre-conference training since past 6 years at Blackhat, and have also taught classes at CanSecWest and Hack in the Box. I am sure we will see a lot more contribution from him going forward.


Last Week – Stefano Di Paola

Next Week – pdp

Monday, May 21, 2007

Reflection on ryan barnett



This week on reflection we have Ryan Barnett from breach security. Ryan is a well respected figure in web application security and is well known for his book “Preventing Web Attacks with Apache”. He is a faculty member for SANS institute and a WASC officer. He is also the Project Lead for the Center for Internet Security Apache Benchmark Project. Ryan has a passion for web application security and has made several contributions to the community. Today he shares with us how he got into the webappsec field and his journey so far. In his own words


“I first realized that I had the hacker’s mindset back in 1999. It was at this time that I got my first real IT consulting gig which was testing a Federal Government’s software for Y2K compatibility. What I found was that I had a knack for identifying input validation issues beyond just whether or not the application would implode if the date field went to 00. After Y2K came and went, the company that I worked for appreciated my Y2K efforts so much that they offered me another position as a Unix Administrator with the same client. I knew a little bit of Unix but not too much about its security. That is when I went to Borders and stumbled upon the two books that would change my career path: Practical Unix and Internet Security and The Cuckoo’s Egg. After gobbling up those books, I was hooked. I wanted to be in security. My first step on this path was when I joined my client’s Computer Security Incident Response Capability (CSIRC) Team. Around this time is also when the SANS Institute was starting to really take off. I took the Hacker Techniques and Incident Response course and obtained the GCIH certification. After successfully helping the client respond to a number of incidents, we then ran into a misconfigured web server allowing anonymous FTP and it quickly turned into a Warez depot. This proved to be a pivotal incident as I was able to work with both the client’s Web Server Admins to track down and fix the problems and setup new monitoring systems (Snort) to identify future issues. It was after this incident that I was offered the position of Web Security and IDS Admin. Basically, they wanted me to be in charge of security within the DMZ segments.

My first real taste of web security came as I was monitoring Snort sensors in DMZ segments and I was constantly weeding out false positives with the web attack signatures. In December of 2001, I was presenting at the SANS Cyber Defense Initiative Conference in Washington D.C. At this conference, they set up a hacker network called ID-Net and I wanted to test the TCP session-resetting capabilities of Snort vs. web attacks. My goal was to try and create a whitelist of allowed URLs and then have Snort pass on these requests. If a requested URL was not listed in the whitelist, Snort would use its Flexible Response capabilities with Libpcap to craft TCP reset packets and try to kill the connections. So, how did Snort perform while under attack on the ID-Net? It did reasonably well; however, the session sniping was not able to effectively terminate all requests that were not in the whitelist file. This was due to a few variables, such as the low network latency and the placement of Snort. One of the main limitations was the actual flexible response code itself. Snort creator Marty Roesch was actually at the SANS CDI conference/ID-Net and I showed him my idea. He liked the concept, but confessed that the Snort session sniping capabilities were probably not fast enough to terminate a malicious HTTP request before it got to the web server. We ran some tests to prove his theory and he was correct. Snort was not able to stop the inbound requests. It did, however perform rather well on the outbound data returned after the web server processed the request. This test did get Marty's wheels turning as he spent a good deal of time while on the ID-Net re-coding the flexible response portion of Snort.

After my adventures with attempting to use Snort for HTTP protection, I realized that in order to provide the best identification and protection, I need to either be inline (reverse proxy) or on the web server itself. I then set out to learn all that I could about Apache security. The research led me to create a hardening checklist for Apache that included many tweaks to the configurations and attempted to leverage Mod_Rewrite for URL filtering and CGI scripts for alerting on malicious traffic. These new configurations proved their worth the next time the Government auditors came a round and attempted their pen-tests. My client was ecstatic that we were able to quickly identify the auditor’s traffic, implement blocking rules and notify them through the proper incident response channels within 5 minutes. After successfully passing that audit, I was flattered to learn that my client’s CSO had provided my hardening information to the other Department Bureaus. Not soon afterwards, I was asked to give a number of presentations on Web Security to the Department and also participating in other Government Security Technical Conferences. A short time later, I met the fine folks at the Center for Internet Security and accepted their offer to lead the Apache Benchmark Project. Over the next few years, I worked my normal job and I also freelanced with the SANS Institute where I both developed and taught classes on Web Security.

It was around 2003 when I had another career altering encounter, even if I didn’t know it at the time, when I was doing research for new Apache Intrusion Detection information and I found an application called ModSecurity. At this time, it was in its early stages however it included many of the advancements and features that I had been left wanting after trying to squeeze every possible ounce of configuration voodoo that I could out of other modules. I immediately started testing it and a kinship with Ivan Ristic quickly developed. I would test ModSecurity and would find bugs and/or request features and Ivan would crank it out almost immediately. As ModSecurity progressed, so did our working friendship as we both wrote separate books on Apache Security and helped each other with reviews and answering questions. We had discussed the possibilities of working together in some capacity but it never worked out. That is until Breach Security acquired Ivan’s company Thinking Stone in late 2006. And that is how I came to work for Breach as the Director of Application Security Training and ModSecurity Community Manager.


Based out of Falls Church, Virginia, Ryan is only 34 years old. Below is a list of his contributions to the webappsec community.


Books:-

Preventing Web Attacks with Apache (Addison-Wesley)
http://www.awprofessional.com/bookstore/product.asp?isbn=0321321286&rl=1

Sample Chapter/Article: Mitigating the WASC Threat Classification with Apache
http://www.awprofessional.com/articles/article.asp?p=442984&rl=1


Articles:-

Quoted In:

May 15, 2007 – InfoWorld (ZeroDay) – “WASC Details Honeypot Project”
http://weblog.infoworld.com/zeroday/archives/2007/05/wasc_details_ho.html

May 4, 2005 – SANS NewsBytes – “Web Server Attacks and Web Site Defacements Up Thirty-Six Percent”
http://www.sans.org/newsletters/newsbites/newsbites.php?vol=7&issue=18#sID314

January 16, 2004 – ComputerWorld – “Opinion: Sticky Security”
http://www.computerworld.com/networkingtopics/networking/story/0,10801,89107,00.html


Contributions:-

ModSecurity Community Manager
http://www.modsecurity.org/

WASC Distributed Open Proxy Honeypot - Project Leader
http://www.webappsec.org/projects/honeypots/

WASC Threat Classification: Contributing Author
http://www.webappsec.org/projects/threat/contributors.shtml

WASC Web Application Firewall Evaluation Criteria: Contributor
http://www.webappsec.org/projects/wafec/

The Center for Internet Security’s Apache Benchmark Document and Scoring Tool
http://www.cisecurity.org/bench_apache.html

The SANS Institute’s Top 20 Vulnerabilities Team
http://www.sans.org/top20/2002/

Sponsored the Honeynet Project’s Scan of the Month Challenge #31
http://www.honeynet.org/scans/scan31/

SecureWorld Conferences - http://www.secureworldexpo.com/

Panel: Facing Off With the Digital Dozen-Technology Challenges Of PCI DSS 1.1

Panel: The Tangled Web: Web Security 2007


Webinars:-

Webcasts: http://www.breach.com/webinars.asp
(ModSecurity Cool Rules, Web Security Threat Report)


Lectures:-

Web Application Security Workshop (Developer/Instructor)

Building a Web Application Firewall Workshop (Developer/Instructor)

Web Intrusion Detection and Prevention with Apache (Developer/Instructor)

Securing and Auditing Apache (Developer/Instructor)

Secure Internet Presence – LAMP (Developer)


Presentations:-

Web Server Fingerprinting

Preventing Website Defacements

Catching Intruders with Snare

ModSecurity: Web Intrusion Detection and Prevention


Memberships:-

WASC Officer
http://www.webappsec.org/officers.shtml

SANS Institute: Courseware Developer, Instructor and Local Mentor
http://www.sans.org/training/instructors.php#Barnett

The Center for Internet Security: Apache Benchmark Project Leader
http://www.cisecurity.org/honor_roll.html

Member of the Counterpane Intelligence Committee
http://www.counterpane.com/alert-cis-ra-0058.html


Blog:-

http://www.modsecurity.org/blog/


Website:-

http://www.breach.com/
http://www.modsecurity.org/


Companies worked for:-

Universal Systems and Technology (Unitech), RS Information Systems, EDS, Breach Security


Company working for:-

Breach Security: http://www.breach.com/
Position Title: Director of Application Security Training


Email:-

Commercial: Ryan_dot_Barnett__@__breach_dot_com
Personal : RCBarnett__@__gmail_dot_com


Ryan has a vast knowledge on web application defense strategies and is also involved in mod security cool rules project. He has started blogging recently and I am sure we will start to see a lot of his original thoughts being shared with the community through his blog.


Last Week – Caleb Sima
Next Week – Stefano Di Paola

Tuesday, May 15, 2007

Reflection on Caleb Sima




This week on reflection we have caleb sima from SPI dynamics. He is the co-founder and CTO of SPI dynamics. He has been involved with internet security since its very early age and is widely respected in the industry. He is often quoted in various magazines and is called upon for his expert opinions. Caleb’s story tells us we can be what we want to be if only we put our minds to it and channel our efforts in the right direction. Caleb is exceptionally talented and at a very young age has achieved so much because of his determination, hard work and dedication.

I guess some other reporter had also done a bit on him before which caleb shared with me along with some other details. His is a very interesting read on how he got into web application security and his journey so far. In his own words


“It started off when I was a kid. I was in trouble a lot in school and with my parents, so restriction was a way of life for me. One day, when I was around 8 or 9 years old, my dad bought a PC and said that I could play on it when I was on restriction, but no games. So I started messing around w/ computers, which started my obsession. Soon afterwards I read something on a friend’s computer about how to make free payphone calls. At this point I become hooked on IT security. I wanted to bypass any security, figure out how to hack into anything electrical from phones to bypassing screensavers. This kicked into my rebellious phase where I got kicked out of multiple schools. It got so bad that my step-dad told me that he would not allow me to touch or read anything about computers. This really sucked as I knew that I wanted to do something with computers when I grew up, so I eventually quit school and ran away from home around the age of 16. I ended up living with one of my best friends and his dad in Jasper, Georgia where the only thing to do was to get in trouble and read books. At the same time though I knew what I wanted to do very early on in life and to me nothing else mattered. So I went and pursued my career in computers and security.

I got to a point where I knew I could get a job with computers somewhere so I started applying. I ended up landing a job on Delk Road in a hole in wall computer repair shop where I was the technician. I was the little Asian kid that fixed your computer when it had problems :). After being there around six months, I went to visit my Mom at her work one day. She introduced me to the network administrator of their company. We hit it off and he offered me a job being a network administrative assistant. Then one day he got fired and a new guy came in to take his place. I became real good friends with the new guy - slept on his couch multiple times. Then one day HR calls me in and fires me claiming that my new boss said I did not do my job. Welcome to my 1st corporate backstabbing. I was furious I went and posted my resume on the Internet and went to the mall. While I was there I received a page (this was when pagers were the “in” thing) that was a recruiter telling me they had a job for me doing network security for a bank. The most perfect job and not even hours after I posted! I called the recruiter and landed my first real security job interview at a company called S1. On the morning of my interview I had one suit to my name, which I wore. It was raining when I left to go to the interview and as I was driving my car (a Chevy Nova of all things – definite piece of junk) I hydroplaned and went into a ditch. So I walked back in the rain three miles to the house, obviously now running late. I woke my friend up and he lent me his suit which was three times too big for me and I drove his car into the interview which was 2.5 hours away.

With all this bad luck, I questioned how the rest of the day would go. Lucky me, my nightmare continued. I walk into this interview and the guy who interviewed me was literally the grouchiest looking old man I had ever seen. He came into the room and shot a round of questions at me like a machine gun, all of which I handled with ease. Then, he just got up and left the room without a word. No smiling, nothing. I just sat in this room not knowing what to do. It was terrible. All I could think was did I just completely do the wrong thing? Should I leave? After about 10 minutes he comes back in and miraculously offers me a job. I then became the security analyst for the world’s first online bank. It was a fantastic job I was able to help implement security for almost all the online banks and my job was to lock down the data center that had most of the major bank transactions going thru it. I ended up learning a great deal about security and it was my first intro into web security. That grouchy old man eventually became a great friend. I still make fun of him today for that interview.

At this stage I was around 17 or 18. I stayed at S1 for a while learning everything about online banking I could. Then one day I was evaluating some new software that claimed it would help protect our network. The software was from a company called Internet Security Systems (ISS). Being the security deviant I was from my years as a kid fascinated with breaking into things, I found huge holes in the software and was able to break the software in various different ways. I notified ISS about these problems and worked with them through various other issues. They liked what I did so much they offered to have me come down and interview with them for a job. This was a time when Internet security was unheard of. I was completely intrigued at the concept of a company solely dedicated to Internet security. I had two full day interviews with the company and they hired me. This was when the company was very small. I joined and became part of their research and development team. ISS became my family of sorts as I basically grew up with them all through the dotcom bubble. I was finally able to experience a company that really appreciated what I contributed and had a lot of fun doing what I did for them because it was something I was really interested in and knew I did well. I also learned a lot about business, which would come to help me in my future endeavors.

Around 2000 when I was about 20, I decided to leave ISS. I noticed that there was huge opportunity in the market for a different kind of security product that no one out there was focused on, but the need was significant. So I left and started doing my own consulting. At the time i was doing a lot of pentests and was breaking in 100% of the time via the web application. All current security products were useless in protecting or finding these flaws. Since most of my work was automated via perl scripts I started to see a way to turn it into a product. The real key moment though was when I was contracting with a large telecom company and the head of security told me that if I could automate what I do he would buy it no questions asked. Thus webinspect was born.

During this time I ran into an old friend from S1. I told him about my idea about a new type of security product. We both decided to hook up and form the company together, so we set-up shop in his house and my apartment. At the same time, I told another friend at S1 who was a very talented security professional about the idea and he wanted to help. So thus SPI Dynamics was created. During the past five years we have gone from an apartment and house to the top floor of a building in the Perimeter area with decks and 180 views of Atlanta, over 100+ employees and our revenue doubling every quarter. Guess I was right – there was a need for this new type of security.

My spare time is usually quite limited, but when I do have some there are a couple things I like to do. My hobby is motorcycles. I ride a 2005 black Yamaha R6 and I ride often. I will usually go up to Vortex in Little Five in atlanta on Thursday nights and hang out and talk with other riders, and on Sundays we usually get a group to go up to Sucches in the North Georgia mountains and hit the curves. I also play poker quite often and hold scratch games at my place every week.”


Based out of Atlanta, GA, Caleb is only 27 years old. He is a member of ISSA and is one of the founding visionaries of the Application Vulnerability Description Language (AVDL) standard within OASIS, as well as a founding member of the Web Application Security Consortium (WASC). Below are some of his contributions to the community


Books:-

Hacking Exposed – Web Applications 2
http://www.webhackingexposed.com/

Sample Chapters:

Attacking Web authorization: Web authorization-Session token security
http://searchsecurity.techtarget.com/generic/0,295582,sid14_gci1210022,00.html

Input Validation Attacks -- Chapter 6, Hacking Exposed Web Applications, Second Edition
http://searchsoftwarequality.techtarget.com/tip/0,289483,sid92_gci1204666,00.html


Articles:-

June 27, 2006 - SearchAppSecurity.com - "Web application security testing reaches new level"
http://searchsoftwarequality.techtarget.com/originalContent/0,289142,sid92_gci1196342,00.html

March 1, 2006 - SearchAppSecurity.com - "Threat modeling key to pro-active security"
http://searchsoftwarequality.techtarget.com/originalContent/0,289142,sid92_gci1169779,00.html

November 20, 2006 and December 11, 2006 - SearchAppSecurity.com Webcast - "Three Application Threats You Can't Afford to Ignore"

November 2006 - SearchAppSecurity.com - "Ask The App Security Expert: Questions & Answers - How to safely deploy Ajax"
http://searchsoftwarequality.techtarget.com/expert/KnowledgebaseAnswer/0,289625,sid92_gci1196901,00.html

January 25, 2007 - SearchAppSecurity.com - "Ask The App Security Expert:
Questions & Answers - Authentication - From passwords to passphrases
http://searchsoftwarequality.techtarget.com/expert/KnowledgebaseAnswer/0,289625,sid92_gci1240747,00.html

Is your site vulnerable to SQL injection attacks?
http://searchsqlserver.techtarget.com/tip/1,289483,sid87_gci1157666,00.html

How do government regulations address application security?
http://searchsoftwarequality.techtarget.com/expert/KnowledgebaseAnswer/0,289625,sid92_gci1163408,00.html

The best way to secure a Web site
http://searchsoftwarequality.techtarget.com/expert/KnowledgebaseAnswer/0,289625,sid92_gci1176981,00.html

Ajax's effect on Web services security
http://searchsoftwarequality.techtarget.com/expert/KnowledgebaseAnswer/0,289625,sid92_gci1163402,00.html

Data breach legislation could affect Web site development
http://searchsoftwarequality.techtarget.com/expert/KnowledgebaseAnswer/0,289625,sid92_gci1186073,00.html

SQL injection: Secure your Web applications
http://searchsoftwarequality.techtarget.com/tip/0,289483,sid92_gci1211973,00.html

Denial of service and Ajax
http://searchsoftwarequality.techtarget.com/expert/KnowledgebaseAnswer/0,289625,sid92_gci1236230,00.html

Automated SQL injection: What your enterprise needs to know - Part 1
http://searchsoftwarequality.techtarget.com/originalContent/0,289142,sid92_gci1157989,00.html

Automated SQL injection: What your enterprise needs to know - Part 2
http://searchsoftwarequality.techtarget.com/generic/0,295582,sid92_gci1227121,00.html

October 19, 2006 - SearchAppSecurity.com - "One simple rule to make your Web apps more secure"
http://searchsoftwarequality.techtarget.com/qna/0,289202,sid92_gci1225425,00.html

October 31, 2006 - SearchAppSecurity.com - "Injection attacks -- Knowledge and prevention"
http://searchsoftwarequality.techtarget.com/generic/0,295582,sid92_gci1227121,00.html

November 30, 2006 - SearchAppSecurity.com Podcast - "Ajax security: A dynamic approach"
http://media.techtarget.com/audioCast/APP_DEVELOPMENT/AppSec_AjaxSecurity_Caleb_2006-11-15.mp3

December 2004 - Security Post - "Are Your Web Applications Secure?"

March 3, 2005 - VNUNET.com - "Bugwatch: Security through the development cycle"
http://www.vnunet.com/vnunet/news/2126891/bugwatch-security-development-cycle

May 15, 2006 - Government Security News (GSN) - "Web Applications: The Hacker's Ultimate Goldmine"
http://www.gsnmagazine.com/may_06_02/guest_columnist.html

July 28, 2006 - ITToolbox.com - "The Software Development Life Cycle:
When to Secure Your Process"
http://research.ittoolbox.com/


Presentations:-

Microsoft TechEd 2006
Microsoft TechEd 2007
http://www.microsoft.com/events/teched2007/default.mspx

Software Security Summit 2007
http://www.s-3con.com/monday.htm

Software Security Summit 2006
Software Security Summit East 2006
http://www.s-3con.com/

RSA 2006
RSA 2007
RSA Europe 2006
http://www.rsaconference.com/

Secure Software Forum 2005
Secure Software Forum 2006
http://www.securesoftwareforum.com/SSF2006/panel_participant.html

Secure Software Forum 2007
http://www.securesoftwareforum.com/SSF2007/panel_participant.html

Blue Hat 2006
http://www.microsoft.com/technet/security/bluehat/sessions/default.mspx

Atlanta Code Camp 2006
http://www.atlantacodecamp.com/

Black Hat USA 2005
Black Hat USA 2006
http://www.blackhat.com/

HP World 2005
HP Technology Forum 2005
HP Technology Forum 2006
http://www.hptechnologyforum.com/about/specialEvents.html

ISSA Georgia 2006
ISSA Austin 2006
ISSA Metro Atlanta Chapter Conference 2006 Charlotte Metro ISSA 2006 Security
http://www.issa.org/

Summit Interz0ne 2005
http://www.interzonewest.com/

(ISC)2 D.C. 2005
(ISC)2 Las Vegas 2005
https://www.isc2.org/cgi-bin/content.cgi?category=86

CarolinaCon 2005
http://www.carolinacon.org/

Techno-Security 2005
http://www.technosecurity.com/html/Techno2005.html

2006 Texas Regional Infrastructure Security Conference University of South Carolina International Event 2007 Regular guest speaker at Georgia Institute of Technology

DHS Software Assurance Forum
https://buildsecurityin.us-cert.gov/daisy/bsi/events/660.html

InfoSec World
http://www.misti.com/default.asp?Page=65&Return=70&ProductID=5539&LS=infosecworld2007


Quoted in:-

September 4, 2004 - The New York Times - "Citing Threats, Entrepreneur Wants to Quit Caller ID Venture"
http://www.nytimes.com/2004/09/04/technology/04caller.html?ex=1252123200&en=68bab740982a4cb1&ei=5088

January 2005 - SC Magazine - "Is your website an easy target?"
http://www.securecomputing.net.au/print.aspx?CIID=62767

January 15, 2005 - SD Times - "Application Security: Mindset Is What Matters"
http://www.sdtimes.com/article/special-20050115-01.html

February 22, 2005 - DevX - "Security Training Falling Through the Education Cracks"
http://www.devx.com/security/Article/27323

February 28, 2005 - Wired - "Known Hole Aided T-Mobile Breach"
http://www.wired.com/politics/security/news/2005/02/66735

April 11, 2005 - Atlanta Business Chronicle - "Blogging the new word-of-mouth for businesses"
http://www.bizjournals.com/atlanta/stories/2005/04/11/smallb2.html

April 18, 2005 - Network World - "Is your cell phone at risk?"
http://www.networkworld.com/research/2005/041805-mobile-virus.html?page=2

April 2005 - CNN - "Top 25 Technology Breakthroughs"
http://transcripts.cnn.com/TRANSCRIPTS/0504/17/cp.01.html

August 1, 2005 - SD Times - "Are Your Web Services Vulnerable?"
http://www.sdtimes.com/article/story-20050801-03.html

August 8, 2005 - Government Computer News (GCN) - "Agencies making little progress against cybervandalism"

January 17, 2006 - eWeek - "SPI Tool Measures Web App Security Risk"
http://www.eweek.com/article2/0,1895,1911830,00.asp

February 15, 2006 - Network World - "Secure software is up to businesses"
http://www.networkworld.com/news/2006/021506-secure-software.html

May 10, 2006 - CNET (and ZDNET) - "Hijacking MySpace for fame and fortune"
http://news.com.com/2100-1038_3-6070533.html

June 6, 2006 - InformationWeek - "Caution, Developers: SOA And Ajax Open To Attack"
http://www.informationweek.com/story/showArticle.jhtml?articleID=188702205

June 12, 2006 - Federal Computer Week (FCW) - "Preventive measures"
http://www.fcw.com/article94828-06-12-06-Print

June 9-15, 2006 - Atlanta Business Chronicle – “SQL injection' attacks on the rise in Atlanta"

June 19, 2006 - InformationWeek - "Yahoo Mail Worm May Be First Of Many As Ajax Proliferates"
http://www.informationweek.com/showArticle.jhtml?articleID=189500060

July 15, 2006 - SD Times - "In War for App Security, New Intelligence on Way"

July 30, 2006 - eWeek - "Vista, Rootkits Headline Hacker Confab"

July 31, 2006 - InternetNews.com - "SQL Injection Threatens to Needle Web Users"
http://www.internetnews.com/security/article.php/3623421

August 3, 2006 - Computerworld - "Black Hat: Blog readers vulnerable to embedded malware"
http://computerworld.com/action/article.do?command=viewArticleBasic&taxonomyName=viruses__worms_and_security_holes&articleId=9002180&taxonomyId=85

August 15, 2006 - SD Times - "Slipping In The Side Door With App Security Message"
http://www.sdtimes.com/article/special-20060815-01.html

August 23, 2006 - CRN - "Keeping Up With The Hackers"

October 23, 2006 - CRN - "Is Oracle Downplaying Security Vulnerabilities?"
http://www.crn.com.au/story.aspx?CIID=67019&src=site-marq

November 27, 2006 - eWeek - "Acunetix Offers New Security Audit Service"
http://www.eweek.com/article2/0,1895,2064320,00.asp

Security overhaul key to Microsoft's software success
http://searchsoftwarequality.techtarget.com/originalContent/0,289142,sid92_gci1193337,00.html

January 12, 2007 - Joe On .NET, Microsoft's Opinionated Misfit Geek - "Upcoming AJAX Security Webcasts"
http://joeon.net/archive/2007/01/12/Upcoming-AJAX-Security-Webcasts.aspx

February 5, 2007 - AccountingWEB.com - "Experts Predict Bad Year Ahead for Cyber-crime, Cyber-terrorism"
http://www.accountingweb.com/cgi-bin/item.cgi?id=103119

February 8, 2007 - VNUNET.com, HackInTheBox.com - "Online apps facing barrage of attacks"
http://www.pcauthority.com.au/news.aspx?CIaNID=45612

February 8, 2007 - Computerworld - "RSA - Hackers find a wealth of victims on corporate sites"
http://www.computerworld.com/action/article.do?command=viewArticleBasic&articleId=9010844&intsrc=article_more_bot


Personal Awards:-

Info Security Products Guide Shaping Info Security 2006 award
http://www.infosecurityproductsguide.com/people/CalebSima.html

Atlanta American Electronics Association (AeA) - Spirit of Endeavor Award for Technology Entrepreneur
http://www.spidynamics.com/news/pr/2004/pr51804.html

Microsoft MVP Award - Developer Security - 2007


Memberships:-

WASC Board Member
http://www.webappsec.org/officers.shtml


Tools written by him:-

Webinspect versions 1-6
SQL Injector
HTTP Editor
Regex Tester
SPI Proxy
SOAP Editor
Web Discovery
Web Brute
Encoders/Decoders


Email:-

Csima__at__spidynamics_dot_com


Website:-

http://www.spidynamics.com/


Contributions:-

WASC Threat Classification
http://www.webappsec.org/projects/threat/


Companies worked for:-

S1, Equant, ISS, SPI Dynamics


Company working for:-

SPI Dynamics
http://www.spidynamics.com/


Caleb is a very active contributor to the community and is also on the Expert Panel of SearchSoftwareQuality.com (formerly SearchAppSecurity.com). He is a man with ideas and vision and I am sure we will see a lot of cool things coming out of his brain.


Last Week – Bill Pennington
Next Week – Ryan barnett

Sunday, May 06, 2007

Reflection on Bill Pennington


This week on reflection, we have Bill Pennington from Whitehat Security. Bill had been involved in web application security for a long time and has performed numerous web application assessments and is currently involved in research and development at Whitehat Security. He has spoken at industry events like blackhat, ISSA LA and OWASP Silicon Valley chapter and has contributed to or co-authored several books.

Bill was involved with OWASP in its early days and is currently a WASC officer. He has a very good sense of humor and is always willing to lend a helping hand. He spends his spare time with his family and kayak fishing. On his reflection, Bill shares with us how he got involved in web application security. In his own words

“I was around 16 with an Amiga 500 and a modem; I spent a lot of time exploring systems that would answer my modem. I got my first internet access in 1990 on a University of Houston machine and spent a lot of time poking around on systems that would talk to me. My roommate at the time got addicted to a MUD and I got addicted to learning about how the internet worked.

For getting into Web Application Security, I blame Caleb Sima from SPI. I was working at a start-up around 1998 doing all the IT/security/blinky light stuff when Caleb was hired to do an audit by a large company that wanted to use my company’s software. Caleb found a few issues with our web application that got me interested. I had mostly been concerned about firewalls and IDS at that point. I figured if Caleb could do it then I could do it :-) I started auditing our software at that point, found a bunch of stuff Caleb missed ;-), and the rest is history.”


Based out of San Jose, CA, Bill is 36 years old. Below are his contributions to the webappsec community


Books:-

Contributed several chapters

Hacker's Challenge: Test Your Incident Response Skills Using 20 Scenarios
http://www.amazon.com/Hackers-Challenge-Incident-Response-Scenarios/dp/0072193840

Co-Authored

Hacker's Challenge 2: Test Your Network Security & Forensic Skills http://www.amazon.com/Hackers-Challenge-Network-Security-Forensic/dp/0072226307/ref=pd_bxgy_b_img_b/104-8852387-4309541

Hacker's Challenge 3
http://www.amazon.com/Hackers-Challenge-3-David-Pollino/dp/0072263040/ref=pd_bxgy_b_img_b/104-8852387-4309541


Presentations/Conferences:-

Challenges of Automated Web Application Scanning - ISSA
http://www.sfbayissa.com/newsletters/SFBAYISSA_2004-01_Newsletter.pdf

The Challenges of Automated Web Application Security – ISACA
http://www.isacala.org/events/mtg0401.html

Latest Attack Trends and Statistics – OWASP San Jose
http://lists.owasp.org/pipermail/owasp-sanjose/2005-September/000029.html

Hacking Web Applications – Blackhat 2003
http://www.blackhat.com/html/win-usa-03/train-bh-win-03-wh.html

Web Application Security - "Reconnaissance, Exploitation, and Investigation" – Blackhat
http://www.blackhat.com/html/win-usa-03/win-usa-03-speakers.html

Taking aim at Web Applications - Blackhat
https://www.blackhat.com/presentations/bh-usa-02/bh-us-02-groves-webapps.ppt


Contributions:-

WASC Threat Classification
http://www.webappsec.org/projects/threat/

WASC Threat Classification Version 2 (under progress)


Memberships:-

WASC Officer
http://www.webappsec.org/officers.shtml#bill_pennington


Company working for:-

WhiteHat Security


Email:-

bill__at__whitehatsec_dot_com


Website:-

http://www.whitehatsec.com/


Companies worked for:-

EDS, RocketCash, Guardent


Bill is a very humble person and is always willing to share his knowledge with others. He mostly works behind the scenes and on a lot of ideas in the labs of whitehat security. Though he doesn’t have a blog yet but I am hoping he would start something soon.

Next Week – Caleb Sima
Last Week – Andrew Van der Stock

Monday, April 30, 2007

Reflection on Andrew Van Der Stock


This week on reflection we have Andrew Van der Stock. Andrew is very active in webappsec industry through OWASP and is involved in a lot of activities including OWASP top ten or OWASP Guide, etc. He has contributed a lot to webappsec field, more so in terms of research and awareness on securing the applications rather then exploiting them. He used to be based out of Australia and has recently moved to Columbia, MD and joined Aspect Security. Today he shares with us his journey with web application security and his thoughts on black hat and white hat hackers (or should I say security professionals). In his own words


”I started playing with computers when I was 7 on a Commodore Pet. My first attempts of squeezing more out of my computer than it probably was capable of was with my Amstrad 6128, which ran a Z80 at 4 MHz. I more than doubled the speed of the 3" (yes, 3") disk drive by driving it directly. This is where I had my first taste of assembly language and low level prodding and probing.

Back in the mid-1990, I was a system administrator at an Australian hospital. Doctors would frequently try to dump private electronic patient (UR) records for their private use, possibly to sell to drug companies, but always illegal. This unregulated (at the time) but
immoral use of our health data infuriated me and got me into ethics and privacy in a big way. This led me to join SAGE-AU, the System Administrator's Guild of Australia, eventually rising to be SAGE-AU's President.

I used to be the editor of SAGE Advice, the SAGE-AU journal, and I ended up writing about 20-30 articles for that. Most are system administration flavored, so not that useful to your readers.

I used to pen a weekly column for the Australian newspaper (a daily national broadsheet in Australia). I think I wrote about 30 odd articles for them back in the day, but their archives are closed to non-subscribers so I can't tell for sure. I lost a lot of data (we all
learn once!) when I went from my early Macs to my SMP workstation running Windows NT 3.51, and I still don't have all my data from that time. Luckily, I'm back on a beautiful Mac again, and as I've learnt the hard lessons of data, I have everything dating back to 1995.

I was the author of most of the technical standards and policy set by auDA, the Australian Domain Name Administrator (similar in function to ICANN). I worked with two or three others for the majority of this project, although as always, we started with many more. My work on this panel regulates how DNS works in Australia.

I never completed my degree. If anyone from RMIT CS is reading, I wouldn't mind getting some credits for my work at OWASP so I can finish it up. Let's talk! If anyone else is interested in offering me a place in masters by research program in web app sec, I'd be interested. I don't think I'm really cut out for undergraduate course work, but I love doing ground breaking research.

I am a dual Microsoft MCSE. My first MCSE was NT 4.0 back in 1997, and then I got my Windows 2000 early adopter MCSE in late 1999 when they were trialing the exams. Early adopters got a nice Gold MCSE card! Many folks find this a bit funny, especially as I've been active in open source for so long... And that I'm really a Mac dude at heart.
But I have a soft spot for Microsoft as they do the basic research in our field, and they own up to security flaws and fix them properly. Now, they're reaping the rewards. Good for them. Many vendors could learn a thing or ten from MS. I'm pretty sure my MCSE's are expired now.

In 1998, I entered the field properly as a security consultant. At that stage, finance institutions were starting to review the lockdown of apps. I was drafted into looking at various apps for many larger finance institutions, who were concerned with unmanaged risk and "mobile code" - ActiveX and Java applets running on their PCs. My interest grew from there, even though I didn't really start code reviewing stuff every day until the early part of this century.

In web app sec, I am completely self taught, but I did learn a lot from folks at OWASP – no one lives in a vacuum. I still do a lot of research using forum software to see how things can be fixed in the real world. I love working with some very smart folks who challenge me every day. It's a sad day when you don't learn or discover something new.

To understand this field, you must understand the threats and attacks to defend against them. I am reasonably certain anyone can learn how to attack if they Think Evil for long enough. It's far easier to Think Evil and destroy than it is to create solid software.

The proof of this putrid state of affairs is s'kid marks getting lots of unthinking column centimeters every day, and yet how little praise the folks in Microsoft got for their work on .NET 2.0. .NET 2.0 advances the field in so many ways – say by automatically rejecting any option in a select list which wasn't sent out in the first place. Whoever thought of that should be on the front page of CNET for a year to make up for the waste of space most "hacking" stories get. And there are so many more unsung heroes - master craftsmen (and women!) all. For every La Padula or Bell or Schneier, there's a thousand or more s'kid marks. This is a very asymmetrical situation and it's not good for our industry.

Criminals who attack systems are simply criminals, or in the abstract, attackers. Low level attackers are "s'kid marks" to me – morons who have a script who think they are the most l33t players. Unfortunately, a million s'kid marks equates to a lot of damage as eventually one or two will strike it lucky during school break.

The true hackers are folks like polymaths like Turing, von Neumann, Douglas Engelbart (the primary creator of the desktop metaphor back in the 1960s), Steve Wozniak (a true hardware hacker), the folks who made my HP 48G calculator (a work of art and mathematical tour de force!), and the recently deceased John Backus (the guy who created Fortran and is the "Backus" in BNF, used in every RFC grammar from here to
eternity). Those folks are worthy of respect and are the true meaning of the word "hacker". But now, the word is lost forever because of constant misuse over a long period of time.

My thing is software engineering as a repeatable practice. We have to stop treating web app sec as a black art. We have to stop lauding the attackers and praising the folks who deliberately break software for nothing more than getting their name in lights. We have to stop thinking these folks are somewhat special. If you're a s'kid mark today, it's time to step up and move on. If you're any good, come join us on the light side of the force – before you commit a crime. There's so much to do and so much research begging for someone to just come and do it.

We should be celebrating the folks who put the hard yards into security research which protects us all – permanently. I'm trying to do this with CSRF at the moment, and will be taking some time this year to make PHP 6.0 safer. I know how to attack software and have done so, but I prefer to build strong software, so my skills lie in ensuring that the defenses and controls I write about, recommend, or indeed implement are robust against known attacks as well as the stuff over the horizon. Occasionally, I am at the horizon, such as when I went and played with JSON injection before pretty much anyone else. I don't claim to have invented JSON injection as it's so totally obvious anyone with half a clue could have recreated my work without any knowledge of what I was doing.

We need more folks who hang out at OWASP and WASC. We should have totally eliminated all forms of injection and other common weaknesses by now - and moved on to where the value lies – the business rules. It's a shame so many are sucked in by the dark side of our industry. It's such a waste of good talent.

I'm one of the dudes working on questions for SANS "National Secure Programming Skills Assessment", a soon to be forthcoming certification which will sort the wheat from the chaff. I'm doing the Java questions (eventually) and hope to be involved in the PHP questions when they kick that off. With some luck, this will not become a paper certification (where certified but clueless folks are rampant), but a suitable metric to prove skill.

I had a book contract to write an Ajax Security Book based upon my world famous Ajax Security Presentation from February last year. However, life intervened, and that's on permanent hold, especially as Billy Hoffman & co is writing what will be a superb Ajax Security book if his research is anything to go by.

I have the bones of a security architecture book waiting to go. If anyone feels like writing it with me, I should be free enough sometime in about two-five years :) Really should finish Guide 3.0 before starting this one though.

I've been involved in open source a long time. My first open source project, which I never completed (shame!) was GNU stty (gstty). Since then, I've been involved in XFree86 (from about 1996 onwards), Linux kernel when things didn't work on my SMP workstation (SMP was rare in the day), on the extreme periphery of NetBSD (my friend Luke was NetBSD core, so I wanted to show a little loyalty to his projects ;), pnm2ppa – print drivers for HP's worst ever printers for Unix/Linux/BSD.

Since 2001, I've been running Aussieveedubbers, a largish VW nut forum. Through that, I got into writing forums. Initially, I helped write XMB, which after a spat became UltimaBB, then GaiaBB, and possibly that code base will be re-forked back into XMB. UltimaBB is very secure compared to its contemporaries as I've been busy with it. However, like all projects using my infinite spare time... Things take a back seat to my real job and my real life.”

Below are his contributions to the webappsec community.

Articles:-

OWASP Guide 2.0 – as lead author and editor.
http://www.owasp.org/index.php/Guide_Table_of_Contents

OWASP Top 10 2007 (along with Dave Wichers and Jeff Williams).
http://www.owasp.org/index.php/Top_10_2007

Many web app sec blog articles:

http://www.greebo.net/?cat=3 (web app sec, 47 blog entries)
http://www.greebo.net/?cat=16 (OWASP, 24 blog entries)
http://www.greebo.net/?cat=17 (conferences and travel)


Memberships:-

Executive Director - OWASP
Columbia PHP user group
SAGE-AU 1995 - 2002, ex-President Jun 2000 – Mar 2001
AISA


Conferences:-

Andrew has presented at the following conferences:

SAGE-AU - The System Administrators Guild of Australia
OWASP – Open Web Application Security ProjectLinux Australia
AusCERT – Australian Computer Emergency Response Team
RuxCon - Australian security conference, Vulnerability assessment and hacking information, for Australia
Black Hat – Black Hat
OSCON – Oreilly Open Source Convention


His favorite presentation is Ajax Security presentation. http://www.greebo.net/owasp/ajax_security.pdf

Predictable ISN numbers in Foundry ServerIron. My first bugtraq advisory back in 2000. So proud!
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0178


Tutored "Internet 101" back in the early 1990's at the Business Faculty at RMIT University


Tools written by him:-

WebSphere {xor} Secret Magic Ring Decoder Toy (C#)

XMB / UltimaBB / GaiaBB – forum software. It's a good test harness for new webappsec ideas. XMB 1.9.7 is due soon which fixes a lot of security issues. (PHP)


Companies worked for:-

Web Application Security jobs:

e-Secure – Senior Security Architect
b-sec – Chief Technologist
National Australia Bank – Security Application Architect
Aspect Security – Senior Engineer


Company working for:-

Aspect Security


Email:-

vanderaj__at__owasp__dot__org



Website:-

http://www.owasp.org


He has one of the sharpest brains in the industry. These contributions above do not reflect the amount of work he has done in promoting awareness in web application security.

Last Week – Nish Bhalla
Next Week – Bill Pennington

Monday, April 23, 2007

Reflection on Nish Bhalla


This week on reflection we have Nish Bhalla from SecurityCompass. Nish has been around the block for a long time and used to work for FoundStone before starting his own company. He is a specialist in product testing, code reviews, web application testing, host and network reviews. He has presented in various conferences, published articles, contributed and co-authored several books. He takes lectures and Webinars at Seneca College , Florida University and has also been quoted in Government Security News, InternetNews and CSO Online.
He has tremendous knowledge in webappsec space and has been involved with OWASP and YASSP. Below is his journey in WebAppSec space in his own words

“I've been interested in security since the mid 90s' pretty much right after I was exposed to UNIX. I started off by developing client / server apps around the same time and tried to hack them. Security knowledge was still considered underground hacker knowledge then and not a whole lot of information was publicly disseminated. I had the opportunity to meet with a few interesting virus writers back at school who taught me a few things about reverse engineering and Clipper the old reversing software (not the clipper programming language).

I started learning about web technologies in the late 90s when I was involved in performing host audits and building secure web servers. I had the opportunity to be involved with the rollout of an online trading company's web application. This was the time where I started getting a good understanding of web applications and how they interact with various components. I took care to understand the technologies and their underlying protocols during this time.

During the same time (in late 90's) I had the opportunity to work for Foundstone. An amazing team of security consultants taught me some new tricks on hacking web applications. I had already learnt a lot about web security when I was involved with the rollout but what these consultants taught me was to adopt a different mind set - the attacker's mind set.

The ease of exploiting of Web Applications was what got me so involved in web app sec (unlike writing buffer overflows which requires a lot more low level knowledge and skills). The code behind the various web application vulnerabilities caught my interest more than just the vulnerabilities themselves.

In 2004 after leaving Foundstone I started Security Compass, which is where I am today. We decided to develop RATS like web code auditing tool; SWAAT (Security Compass Web Application Analysis Tool) to help with doing some basic server page code auditing.

We're currently involved in doing some interesting research on web services and we'll be coming out with interesting web services tools in the near future.

I'm a big snooker/pool fan; living in Toronto provides me with the chance to meet a lot of interesting people.”


Based out of Toronto, CA, Nish is 33 years old. Below are his contributions to the community.


Articles:-

Writing Stack Based Overflows on Windows
http://www.securitycompass.com/resources/StackBasedOverflows-Windows-Part1.pdf
http://www.securitycompass.com/resources/StackBasedOverflows-Windows-Part2.pdf
http://www.securitycompass.com/resources/StackBasedOverflows-Windows-Part3.pdf
http://www.securitycompass.com/resources/StackBasedOverflows-Windows-Part4.pdf

AIX 4.3 Bastion Host Guidelines
http://www.giac.org/certified_professionals/practicals/gsec/0853.php

Building Secure Applications: Consistent Logging
http://www.securityfocus.com/infocus/1888

IIS Lockdown and Urlscan
http://www.securityfocus.com/infocus/1755


Books:-

Co-authored

Buffer Overflow Attacks
http://www.amazon.com/gp/product/1932266674/


Contributed

Hacking Exposed Web Applications, Second Edition
http://www.amazon.com/gp/product/0072262990

HackNotes(tm) Network Security Portable Reference
http://www.amazon.com/gp/product/0072227834/

Windows(R) XP Professional Security
http://www.amazon.com/gp/product/0072226021/

Writing Security Tools and Exploits
http://www.amazon.com/gp/product/1597499978


Conferences:-

Web Service Vulnerabilities
http://www.blackhat.com/html/bh-europe-07/bh-eu-07-index.html

Application Security - Dallascon
http://www.dallascon.com/

Federations of Security Professionals
http://www.fspgroup.ca/

Binary Analysis, Finding Secret in ISAPIs - 2006
http://www.syscan.org/

Preparing for a FISMA Compliancy Audit: What IT Security Professional Needs to Know
http://www.infosecurityevent.com/App/homepage.cfm?moduleid=42&appname=100004

Finding Secrets in ISAPI
http://conference.hackinthebox.org/hitbsecconf2006kl/

Auditing Source Code
http://2005.recon.cx/


Other Contributions:-

OWASP Toronto Local Chapter
http://www.owasp.org/index.php/Toronto

SWAAT
http://www.owasp.org/index.php/Category:OWASP_SWAAT_Project

Yet Another Solaris Security Project
http://www.yassp.org/yassp/


Company working for:-

Security Compass


Email:-

nish__at__securitycompass_dot_com


Website:-

www.securitycompass.com


Companies worked for:-


Foundstone, Infotek Solutions


Education:-

Masters in Parallel Processing from Sheffield University,
Post graduation in Finance from Strathclyde University,
Bachelor in Commerce from Bangalore University



Nish is currently working on some very interesting tools and hopefully will be released soon which are definitely worth evaluating.

Last Week – Ory Segal
Next Week – Andrew Van Der Stock

Friday, April 06, 2007

Reflection on Chris Shiflett



This week on reflection we have Chris Shiflett. One of the very few people who have been blogging on webappsec for a long time and I am sure is amongst the top 10 visited blog on web application security. His knowledge on web application security is tremendous and his blog is a goldmine for people who are looking to learn and understand various types of web application vulnerabilities and their solutions. He has spoken at numerous conferences, published several articles and even written few books.

Chris shares with us how he got started with web application security field and how he got involved with PHP security consortium. In his own words

“I've been an avid web enthusiast since the early 90s, although the first couple of years were mostly spent exploring the technologies involved, particularly HTTP. Web application security is a natural extension of my ongoing desire to apply creativity to a solid fundamental understanding of technology. I started programming on a Commodore 64 in the early 80s, but it wasn't until the early 90s that I focused my attention on web technologies.

The PHP Security Consortium is a group of people whose focus is educating the PHP community about web application security. It began with a simple post on my blog in 2004 requesting assistance with some research I was conducting at the time. (I was researching worms that combine XSS and CSRF, an idea later brought to life by the Myspace worm.) To date, members of the PHP Security Consortium have written books and articles, spoken at industry-leading PHP and open source conferences, and collaborated on projects like the PHP Security Guide and PHPSecInfo. Very little of our work promotes the group itself, because our focus is helping people.

I'm an avid soccer fan. Living in New York provides me with the chance to play with skilled players from all over the world, so I spend almost every weekend in the park. My wife runs marathons and occasionally convinces me to run with her, but I prefer soccer. :-) “



Based out of Brooklyn, NY, USA, Chris is only 30 years old (I cannot believe so many leading people in webappsec field are below 30, which is a very promising sign for the industry). Below are his contributions to the webappsec community.


Books:-

Essential PHP Security (O'Reilly, 2005)
http://phpsecurity.org/

HTTP Developer's Handbook (Sams, 2003)
http://shiflett.org/books

Contributions to other books

Programming PHP (O'Reilly 2006)
http://www.amazon.com/Programming-PHP-Rasmus-Lerdorf/dp/1565926102

PHP Cookbook (O'Reilly 2006)
http://www.oreilly.com/catalog/phpckbk2/

PHP in Action (Manning, 2007)
http://www.manning.com/reiersol/


Articles (WebAppSec only):-

Note: This is a subset of articles that are at least tangentially
related to web application security.

The articles without the link were published in PHP architect magazine and are available only upon subscription. The dates are mentioned along with the article (in case you want to look up that particular issue of the magazine). You can also find the information on his blog though.

Security Corner: Security Testing - 19 Dec 2006

Security Corner: Cross-Domain Ajax - 16 Oct 2006

Security Corner: Understanding Superglobals - 25 Jul 2006

Security Corner: Character Encoding - 28 Feb 2006

Security Corner: Email Injection - 25 Jan 2006

Security Corner: Context - 22 Dec 2005

Security Corner: Cross-Site Scripting - 21 Nov 2005

Security Corner: HTTP Response Splitting - 25 Oct 2005

Security Corner: Code Audits - 21 Sep 2005

Security Corner: Theory - 18 Jul 2005

Security Corner: Persistent Logins - 25 May 2005

Security Corner: BBCode - 19 Apr 2005

Security Corner: Magic Quotes - 21 Mar 2005

Security Corner: PHP Security Consortium - 15 Feb 2005

Guru Speak: Storing Sessions in a Database
http://shiflett.org/articles/storing-sessions-in-a-database

Security Corner: Cross-Site Request Forgeries
http://shiflett.org/articles/cross-site-request-forgeries

Security Corner: Ideology
http://shiflett.org/articles/ideology

Guru Speak: How to Avoid "Page Has Expired" Warnings
http://shiflett.org/articles/how-to-avoid-page-has-expired-warnings

Security Corner: File Uploads
http://shiflett.org/articles/file-uploads

Security Corner: Secure Design
http://shiflett.org/articles/secure-design

Security Corner: Session Hijacking
http://shiflett.org/articles/session-hijacking

Security Corner: Form Spoofing
http://shiflett.org/articles/form-spoofing

Security Corner: Input Filtering
http://shiflett.org/articles/input-filtering

Security Corner: SQL Injection
http://shiflett.org/articles/sql-injection

Security Corner: Shared Hosting
http://shiflett.org/articles/shared-hosting

Security Corner: Session Fixation
http://shiflett.org/articles/session-fixation

The Truth about Sessions
http://shiflett.org/articles/the-truth-about-sessions

Foiling Cross-Site Attacks
http://shiflett.org/articles/foiling-cross-site-attacks

Passport Hacking Revisited
http://shiflett.org/articles/passport-hacking-revisited

Passport Hacking
http://shiflett.org/articles/passport-hacking


Lectures / Talks:-

Almost all of the below mentioned talks you can find reference on chris’s blog. I tried to get the links but everytime i got sidetracked with something on his blog and eventually ran out of time. For the links, please check back again later or you can search on this blog (http://shiflett.org)

PHP Under Attack - OSCON (10 Jul 2003)

PHP Attacks and Defense – ApacheCon (19 Nov 2003)

PHP Security - OSCON (26 Jul 2004)

Foiling Cross-Site Attacks - OSCON (29 Jul 2004)

Securing PHP Sessions - OSCON (30 Jul 2004)

PHP Session Security - phpworks (23 Sep 2004)

Testing PHP with Perl - New York PHP (26 Oct 2004)

PHP Security - ApacheCon (14 Nov 2004)

Testing PHP with Perl - ApacheCon (16 Nov 2004)

PHP Security - PHP Quebec (30 Mar 2005)

PHP Security Briefing - PHP Quebec (01 Apr 2005)

PHP Security Briefing - NOAA SecCon (04 May 2005)

PHP Security by Example - phptropics (13 May 2005)

PHP Security Audit HOWTO - PHP West (11 Jun 2005)

PHP Security - ApacheCon Europe (19 Jul 2005)

PHP Security Briefing - ApacheCon Europe (21 Jul 2005)

Testing PHP with Perl - ApacheCon Europe (22 Jul 2005)

PHP Security - OSCON (01 Aug 2005)

PHP Security Briefing - OSCON (03 Aug 2005)

PHP by Example - phpworks (14 Sep 2005)

PHP Security by Example - phpworks (15 Sep 2005)

PHP Security Audit HOWTO - New York PHP (27 Sep 2005)

PHP Security Audit HOWTO - Boston PHP (06 Oct 2005)

PHP Security - ZendCon (18 Oct 2005)

PHP Security Audit HOWTO - ZendCon (21 Oct 2005)

Power PHP Testing - ApacheCon (11 Dec 2005)

Agile PHP Testing - PHP Quebec (31 Mar 2006)

What's New in PHP 5 - LinuxWorld (25 Apr 2006)

PHP Security - LinuxWorld (25 Apr 2006)

PHP Security - phptek (27 Apr 2006)

Zend Framework - Boston PHP (04 May 2006)

Essential PHP Security - ApacheCon Europe (27 Jun 2006)

The Truth about XSS - ApacheCon Europe (28 Jun 2006)

Agile PHP Testing - ApacheCon Europe (29 Jun 2006)

Power PHP Testing - OSCON (24 Jul 2006)

Essential PHP Security - OSCON (25 Jul 2006)

The Truth about XSS - OSCON (26 Jul 2006)

PHP Security Testing - OSCON (27 Jul 2006)

The Truth about XSS - phpworks (13 Sep 2006)

Agile PHP Testing - phpworks (13 Sep 2006)

PHP Security Audit HOWTO - EuroOSCON (21 Sep 2006)

PHP Security Testing - DC PHP Con (19 Oct 2006)

The Truth about XSS - DC PHP Con (19 Oct 2006)

Essential PHP Security - ZendCon (30 Oct 2006)

Security 2.0 - Web Builder 2.0 (05 Dec 2006)

The Truth about Sessions - PHP Quebec (15 Mar 2007)


Memberships:-

PHP Security Consortium (Founder)
http://phpsec.org/

Open Web Application Security Project
http://owasp.org/

Web Application Security Consortium
http://webappsec.org/


Companies worked for:-

USPS, eDonkey, Brain Bulb, OmniTI


Company working for:-

OmniTI (Principal)
http://omniti.com/


Email:-

http://shiflett.org/contact


Blog:-

http://shiflett.org/


Websites:-

Personal -

http://shiflett.org/

Work -

Omni TI
http://omniti.com/

PHP Security Consortium
http://phpsec.org/

Essential PHP Security
http://phpsecurity.org/


Education:-

BS in Computer Science


If you haven’t been to his blog yet, then I would strongly recommend visiting it sooner as you will find plethora of information on webappsec. Every webappsec enthusiast should have it on their watchlist.

Last Week - Jeff Willians
Next Week - Ory Segal