Главная
Study mode:
on
1
Introduction
2
attackers know this too
3
current strategies
4
stop gap
5
Middleware
6
Use Cases
7
Java
8
Wrapping
9
HTTP Modules
10
Network Requests
11
Finding Hooks
12
Trampoline Use
13
Kali and Method Replacement
14
Efficiency
15
Demo
16
Profiling API
17
Demonstration
18
Wrapup
Description:
Explore techniques for enhancing application security through automatic code injection in this 44-minute conference talk from AppSecUSA 2015. Learn how to leverage hooking vulnerable code paths in production applications to introduce additional security layers without requiring developer intervention or application recompilation. Discover specific examples of hooking Java, .NET, and Ruby frameworks as presenters Richard Meester and Joe Rozner demonstrate innovative approaches to combat the challenges of detecting and remediating all vulnerabilities before release. Gain insights into semantic analysis tools, novel integration technology, and runtime patching methods to improve protection against XSS and SQL injection attacks.

Sinking Your Hooks in Applications

OWASP Foundation
Add to list
0:00 / 0:00