Jeremiah Grossman

/Tag:Jeremiah Grossman

Profiting From Business Logic Flaws

Yesterday Jeremiah Grossman and Trey Ford from WhiteHat Security gave a very interesting and fun presentation called 'Get Rich or Die Trying - Making Money on The Web, The Black Hat Way'. They went over several real world examples of business logic flaws, and in some cases profited (a lot) from those flaws. The Get [...]

2017-03-12T17:40:23-07:00 August 8th, 2008|Security Conferences|0 Comments

Web Application Security Survey Results

A couple weeks ago, Jeremiah Grossman put together a survey for web application security professionals, and now the results are posted. There were 17 questions, ranging from your general background to rating web vulnerability scanners. There were some funny questions like the HackerSafe one... Safe from Hackers, Safe for Hackers, or Other? Jeremiah also posted [...]

2017-03-12T17:40:25-07:00 July 26th, 2008|Vendor News|0 Comments

SANS WhatWorks Summits

Last week SANS held two WhatWorks summits in Las Vegas. One covered penetration testing and ethical hacking, and the other covered web application security.   Jeremiah Grossman was the keynote speaker for the web application security summit, and he posted his post-summit thoughts on his blog. The format favored enterprise speakers rather than experts, which [...]

2017-03-12T17:40:26-07:00 June 10th, 2008|Security Workshops|0 Comments

Hack in the Box: Dubai

Last week was the Hack in the Box conference, this time in Dubai. I wish I could have been there, but its a bit hard for me to justify the international travel costs. But the speaker lineup and topics looked awesome, covering things like GSM cracking, windows token kidnapping, and Medeco m3 cracking. Speaking of [...]

2017-03-12T17:40:28-07:00 April 24th, 2008|Security Conferences|1 Comment

Session Impressions @ RSA

I thought I had an excellent plan when attacking the massive number of RSA sessions available. My plan was to attend the sessions unique to RSA, mainly the business sessions because I already attend a handful of technical security conferences throughout the year. Here is a my original RSA schedule, and I none of them [...]

2017-03-12T17:40:28-07:00 April 12th, 2008|Security Conferences|0 Comments