Found this useful? Then Digg It.
Found this useful? Then Digg It.
Today I am speaking at the EUSecWest/core06 security conference in London on "Practical Automated Web Application Attack Techniques". You can find my presentation here.
Also, here are the example files, parseLog.pl (which for some reason is not on the O'Reilly site), simpleScanner.pl, and extendedScanner.pl.
Found this useful? Then Digg It.
Found this useful? Then Digg It.
Just to note that the slide decks from the EuSecWest/core06 conference earlier this year are now available. You can obtain them from the EuSecWest site. My slides are not currently up there, although they should be soon. In the mean time, my slides and examples are available on my site.
You can also refer back to my blogged coverage of Day 1 and Day 2 of the conference on this site. Enjoy!
Found this useful? Then Digg It.
I've just got back from Brussels, after having spoken at the SANS Community Night last night on "Practical Automated Web Application Attack Techniques". You should now be able to download the slidedeck, as well as the tools from Network Security Tools that I demonstrated - parseLog.pl (which for some reason is not on the O'Reilly site), simpleScanner.pl, and extendedScanner.pl.
You can also find SQLBrute, as well as my page showing an example of using SQLBrute (which is what I demoed) as well. Enjoy!
Found this useful? Then Digg It.
I got an email this morning (and a comment on an IM conversation a week ago) that has continued to remind me that I've been neglecting this blog. So I thought I'd pen a quick update to let everyone know whats going on and coming up.
First of all, I got my turbo talk to Blackhat USA in Las Vegas accepted, so I'll be speaking there again for the first time since 2004. The paper is called "SQL Injection Worms for Fun and Profit", and appears to be even more timely than I expected when submitting it considering what is still an ongoing problem. I'll be in Vegas for both Blackhat and Defcon if anyone wants to plan a catch up.
On other news, I've made little progress on rewriting SQLBrute in .NET due to a lack of time. I am, however, going to release SQLBrute 1.1 in Python in the not too distant future - I'm adding Sybase support, and cleaning up a few of the routines. Also, check out the port of Microsoft's AntiXSS library to Java - you can check it out on the GDS Tools page.
Thats all for now - more news and happenings soon!
Found this useful? Then Digg It.
As some of you may be aware, I used to work for the Ernst & Young Advanced Security Center in New York (and in Houston before that). Having a quick look at the speakers list for Blackhat in Las Vegas as they are confirmed it amused me that so many of the old E&Y ASC crew are represented in the speakers list:
Found this useful? Then Digg It.
Random followup - I found a photo of myself taken while I was onstage in Vegas (this is from the Armorize blog I think?). I find it amusing I can almost read my t-shirt - "I am Jack's Overwritten Stack Pointer...". That one is from Defcon 9 or 10 I think :-)

Found this useful? Then Digg It.
Quick note - I'm currently confirmed for the following speaking engagements. If anyone is attending any of these and wants to catch up, drop me an email.
Found this useful? Then Digg It.
This page contains an archive of all entries posted to justinclarke.com in the Speaking category. They are listed from oldest to newest.
PocketPC is the previous category.
Useful Links is the next category.
Many more can be found on the main index page or by looking through the archives.