28.10.2014 Views

SQL Injection Attacks and Defense - 2009

SQL Injection Attacks and Defense - 2009

SQL Injection Attacks and Defense - 2009

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

exploiting, <strong>and</strong> correcting software security flaws. Prior to founding GDS,<br />

Mr. Hemler was a senior security engineer at Ernst & Young’s Advanced<br />

Security Center.<br />

Mr. Hemler has authored source code analysis tools <strong>and</strong> written<br />

multiple scripts for identifying <strong>and</strong> exploiting network <strong>and</strong> web<br />

application vulnerabilities. He is a contributing author to books in<br />

the area of application security, frequently blogs on the GDS Security<br />

Blog, <strong>and</strong> often speaks at various information security conferences <strong>and</strong><br />

training seminars. Mr. Hemler graduated with a Bachelors of Business<br />

Administration from the University of Notre Dame.<br />

Alex<strong>and</strong>er Kornbrust is the founder of Red-Database-Security.<br />

He provides Oracle security audits, security training <strong>and</strong> consulting<br />

to customers worldwide.<br />

Alex<strong>and</strong>er has worked since 1992 with Oracle <strong>and</strong> his specialties are<br />

the security of Oracle databases <strong>and</strong> secure architectures. Alex<strong>and</strong>er has<br />

reported more than 300 security bugs to Oracle.<br />

Alex<strong>and</strong>er holds a masters degree (Diplom-Informatiker) in computer<br />

science from the University of Passau.<br />

Haroon Meer is the Technical Director of SensePost. He joined SensePost<br />

in 2001 <strong>and</strong> has not slept since his early childhood. He has played in most<br />

aspects of IT Security from development to deployment <strong>and</strong> currently gets<br />

most of his kicks from reverse engineering, application assessments, <strong>and</strong><br />

similar forms of pain. Haroon has spoken <strong>and</strong> trained at Black Hat, Defcon,<br />

Microsoft Tech-Ed, <strong>and</strong> other conferences. He loves “Deels,” building new<br />

things, breaking new things, reading, deep find-outering, <strong>and</strong> making up<br />

new words. He dislikes sleep, pointless red-tape, dishonest people, <strong>and</strong><br />

watching cricket.<br />

Gary O’Leary-Steele (CREST Consultant) is the Technical Director of<br />

Sec-1 Ltd, based in the UK. He currently provides senior-level penetration<br />

testing <strong>and</strong> security consultancy for a variety of clients, including a number<br />

of large online retailers <strong>and</strong> financial sector organizations. His specialties<br />

v

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!