(logo)
(navigation image)
Home Animation & Cartoons | Arts & Music | Computers & Technology | Cultural & Academic Films | Ephemeral Films | Home Movies | Movies | News & Public Affairs | Non-English Videos | Open Source Movies | Prelinger Archives | Spirituality & Religion | Sports Videos | Videogame Videos | Vlogs | Youth Media

Search: Advanced Search

Anonymous User (login or join us)Upload

View movie

[item image]
View thumbnails

Play / Download (help[help])

(51 MB)Ogg Video
(89 MB)512Kb MPEG4
(153 MB)Cinepack


All Files: HTTP

Resources

Bookmark

Automatic Security Testing with Static and Dynamic Analysis

Most Drupal security vulnerabilities are discovered via manual code reviews or by accident. This session will introduce two automated approaches to detecting Cross-Site Scripting (XSS) and SQL Injection (SQLi) security vulnerabilities and present progress to date in applying them to Drupal. Dynamic Analysis, or "data tainting," involves tagging actual data within a running program received from untrusted sources as "tainted," propagating the taintedness to any data derived from tainted data, and detecting when tainted data is used in dangerous circumstances. For example, data tainting would detect when any data derived from unsanitized GET request parameters is outputted within HTML. Static Analysis involves performing data-flow analysis directly on source code to detect when certain kinds of security vulnerabilities are possible. Like Dynamic Analysis it sometimes uses a data tainting model but instead of operating within a live running program on real data it studies all possible code paths within a program to identify potential problems. Both dynamic and static analysis techniques have proved effective at identifying security vulnerabilities in Drupal. This session will describe how both techniques work and show examples of problems each has found.


This movie is part of the collection: Open Source Movies

Audio/Visual: sound, color
Keywords: drupalcon2008szeged


Individual Files

Movie FilesCinepackOgg Video512Kb MPEG4
Drupalcon_2008_Szeged_aug_30_4_Acquia_2pass.avi153 MB51 MB89 MB

Be the first to write a review
Downloaded 172 times
Reviews


Terms of Use (10 Mar 2001)