Главная
Study mode:
on
1
Introduction
2
What is the Magical Code Injection Rainbow
3
What are vulnerable applications
4
Limitations of vulnerable applications
5
Testbeds
6
Anti XSS
7
XMLMAO
8
Crypt OMG
9
Web Site
10
Reusing Keys
11
Encryption
12
Shell Injection
Description:
Explore advanced exploitation techniques in this 43-minute LASCON conference talk from 2013. Delve into the Magical Code Injection Rainbow (MCIR) framework for building configurable vulnerable applications. Learn about SQLol for SQL injection and XMLmao for XML and XPath injection. Discover advanced techniques in SQL injection, XPath injection, cross-site scripting, and shell command injection. Examine the exploitation of insecure cryptosystems and gain insights on creating your own configurable vulnerable application using the MCIR framework. Cover topics such as testbeds, Anti XSS, XMLMAO, cryptography, web security, key reuse, encryption, and shell injection.

Riding the Magical Code Injection Rainbow

LASCON
Add to list
0:00 / 0:00