Hacking web apps

Aino Andriessen

On JavaPolis 2004 Erwin Geirnaert did a very nice presentation on hacking Web Applications. He gives an overview of how this can be achieved and then he gives some very nice examples for WebSphere and Weblogic. But my favorite is the website where he only changes the parameter patientId=12345 to patientId=* and gets the data of all patients. It is stunning to see how easy it can be to actually get access to the server itself or to retrieve confidential information and it should be a warning to all application server administrators and web developers. The presentation can be viewed on line.

Next Post

Feuerstein is coming to Amsterdam

On september 8, 2005 Quest Software will organize a training seminar in Amsterdam by Steven Feuerstein. It will cover two topics: 1. Correcting PL/SQL Worst Practices and 2. Survey of Oracle Database 10g PL/SQL New Features. Without doubt his sessions are worthwhile, entertaining and memorable. Related posts: Apache MyFaces (open […]
%d bloggers like this: