28.10.2014 Views

SQL Injection Attacks and Defense - 2009

SQL Injection Attacks and Defense - 2009

SQL Injection Attacks and Defense - 2009

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

include web application security assessment, network penetration testing<br />

<strong>and</strong> vulnerability research. Gary is also the lead author <strong>and</strong> trainer for the<br />

Sec-1 Certified Network Security Professional (CNSP) training program<br />

that has seen more than 3,000 attendees since its launch.<br />

Gary is credited by Microsoft, RSA, GFI <strong>and</strong> Marshal Software for the<br />

discovery of security flaws within their commercial applications.<br />

Alberto Revelli is a security researcher <strong>and</strong> the author of sqlninja, an open<br />

source toolkit that has become a “weapon of choice” when exploiting<br />

a <strong>SQL</strong> <strong>Injection</strong> vulnerability on a web application based on Microsoft<br />

<strong>SQL</strong> Server. As for his day job, he works as a senior security consultant for<br />

Portcullis Computer Security, mostly breaking into web applications <strong>and</strong><br />

into any other thing that happens to tickle his curiosity.<br />

During his career he has assisted a multitude of clients including<br />

major financial institutions, telecom operators, media <strong>and</strong> manufacturing<br />

companies. He has been invited as a speaker to several security conferences,<br />

including EuSecWest, CONFidence, Shakacon, <strong>and</strong> SOURCE. He is the<br />

Technical Director of the Italian Chapter of OWASP <strong>and</strong> he is one of the<br />

authors of the OWASP Testing Guide. Prior to joining Portcullis, Alberto<br />

worked for Spike Reply <strong>and</strong> McKinsey&Company.<br />

He currently resides in London, enjoying its awful weather <strong>and</strong> its<br />

crazy nightlife together with his girlfriend.<br />

Marco Slaviero (MSc) is an associate at SensePost, a South African<br />

information security company focused on providing penetration<br />

testing services to global clients in the financial services, mining <strong>and</strong><br />

telecommunications sectors. Marco specializes in web application<br />

assessments with a side interest in thick applications <strong>and</strong> network<br />

assessments.<br />

Marco has spoken on <strong>SQL</strong> <strong>Injection</strong> at Black Hat USA, <strong>and</strong> he<br />

developed the proof-of-concept Squeeza tool.<br />

Marco lives with Juliette, his wonderful wife, who gave him the<br />

space to contribute to this book.<br />

vi

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!