28.10.2014 Views

SQL Injection Attacks and Defense - 2009

SQL Injection Attacks and Defense - 2009

SQL Injection Attacks and Defense - 2009

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Contributing Authors<br />

Rodrigo Marcos Alvarez (MSc, BSc, CREST, CISSP, CNNA, OPST,<br />

MCP) is the founder <strong>and</strong> technical director of SECFORCE. SECFORCE<br />

is a UK-based IT security consultancy that offers vendor-independent <strong>and</strong><br />

impartial IT security advice to companies across all industry fields.<br />

Rodrigo is a contributor to the OWASP project <strong>and</strong> a security researcher.<br />

He is particularly interested in network protocol analysis via fuzzing testing.<br />

Among other projects, he has released TAOF, a protocol agnostic GUI fuzzer,<br />

<strong>and</strong> proxyfuzz, a TCP/UDP proxy which fuzzes on the fly. Rodrigo has<br />

also contributed to the web security field by releasing bsishell, a python<br />

interacting blind <strong>SQL</strong> injection shell <strong>and</strong> developing TCP socket reusing<br />

attacking techniques.<br />

Dave Hartley has been working in the IT security industry since 1998.<br />

He is currently a security consultant for Activity Information Management,<br />

based in the United Kingdom, where he is responsible for the development<br />

<strong>and</strong> delivery of Activity’s technical auditing services.<br />

Dave has performed a wide range of security assessments <strong>and</strong> provided<br />

a myriad of consultancy services for clients in a number of different sectors,<br />

including financial institutions, entertainment, media, telecommunications,<br />

<strong>and</strong> software development companies <strong>and</strong> government organizations<br />

worldwide. Dave is a CREST certified consultant <strong>and</strong> part of Activity’s<br />

CESG CHECK team. He is also the author of the Bobcat <strong>SQL</strong> injection<br />

exploitation tool.<br />

Dave would like to express heartfelt thanks to his extremely beautiful<br />

<strong>and</strong> underst<strong>and</strong>ing wife Nicole for her patience <strong>and</strong> support.<br />

Joseph Hemler (CISSP) is a co-founder <strong>and</strong> Director of Gotham Digital<br />

Science, an information security consulting firm that works with clients to<br />

identify, prevent, <strong>and</strong> manage security risks. He has worked in the realm of<br />

application security for over 9 years, <strong>and</strong> has deep experience identifying,<br />

iv

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!