For my next trick... hacking Web2.0 ( lite ) Petko D. Petkov (pdp) GNUCITIZEN http://www.gnucitizen.org
powered BY http://www.gnucitizen.org
...before we START Feel free to ask questions! Do ask questions! Have fun!
what is WEB2.0?
... Marketing buzzword Invented by O'Reilly Media in 2003 Wikis, Blogs, AJAX, Social Networks, Collaboration APIs, SOA (Service Oriented Architecture) Data in the Cloud Applications on Demand
why web2.0 HACKING?
... Data Management Information Leaks Live Profiling Information Spamming Service Abuse Autonomous Agents Distribution Attack Infrastructures
the PAPER 5 fictional stories with technology that is real Learn by example KISS (Keep it Simple Stupid) Problems with no solutions I was told that I need to come up with some solutions, otherwise I cannot present at OWASP.
the STORIES MPack2.0 Attack Infrastructures Wormoholic Autonomous Agents Bookmarks Rider Distribution RSS Kingpin Information Spamming Revealing the hidden Web Service Abuse
know your ROOTS
... what's MPACK?
... what would it be in the web2.0 WORLD? hint: Google Mashup Editor
... who is SAMY?
... what's a covert CHANNEL?
... ...but in the web2.0 WORLD?
... who's the mechanical TURK?
... ...to MALWARE? hint: Social Bookmarking
... can web2.0 malware BROADCAST?
... ...MD5(DOMAIN + TIME)
... where are my SCHEDULERS?
... where are my ACTUATORS?
... ...data in the CLOUD... (the malicious one)
... ...applications on DEMAND... (the malicious ones)
... what's state and what's PERSISTENCE?
... riding social bookmarks is FUN!
... ...maybe make some money TOO!
... to splog or not to splog. This is the QUESTION!
... call me the rss KINGPIN!
... service abuse and the hidden WEB
know your ROOTS
...more Profiling targets by watching their Web activities Snoop onto targets GEO Position Mobile phones GEO Position individuals More service abuse More vulnerabilities More Insecurities
... solutions and recommendations?
thank YOU http://www.gnucitizen.org

More Related Content

PPT
PPT
六上 閱讀計畫
PPT
2. Primeros Pasos
PPT
Revista
PPS
23 Apos Pentecostes 2007
PPS
Antrtida Rctd
PPT
ANALISIS OCUPACIONAL PARTICIPATIVO
PPT
Fútbol Sala Temporada 2006 07
六上 閱讀計畫
2. Primeros Pasos
Revista
23 Apos Pentecostes 2007
Antrtida Rctd
ANALISIS OCUPACIONAL PARTICIPATIVO
Fútbol Sala Temporada 2006 07

Similar to GNUCITIZEN Pdp Owasp Usa 2007 (20)

PPT
GNUCITIZEN Pdp Owasp Day September 2007
PDF
Hack the book Mini
PDF
Hacking the Company : Risks with carbon-based lifeforms using vulnerable systems
PDF
Hackers secrets
PDF
Digital Culture - Web Evolution
PPTX
SecTor '09 - When Web 2.0 Attacks!
PDF
HoneyPy & HoneyDB (LASCON 2016)
PDF
Hacker halted2
PDF
Meetup 6/3/2017 - Artificiële Intelligentie: over chatbots & robots
PPTX
Its the app stupid - CloudStack 2014 Collaboration Conference #CCNA14
PPTX
Practical exploitation and social engineering
PDF
Teaching Elephants to Dance (Federal Audience): A Developer's Journey to Digi...
PDF
Attacker Ghost Stories - ShmooCon 2014
PDF
Strategies for securing your banks & enterprises (from someone who robs bank...
PDF
hacking into computer systems - a beginners guid
ODP
Oscon 2008 Open Micro Blogging Presentation
PDF
Hacking For Innovation
PPT
Web Application Hacking
PDF
Secular Technological Tailwinds
PDF
Von JavaEE auf Microservice in 6 Monaten - The Good, the Bad, and the wtfs...
GNUCITIZEN Pdp Owasp Day September 2007
Hack the book Mini
Hacking the Company : Risks with carbon-based lifeforms using vulnerable systems
Hackers secrets
Digital Culture - Web Evolution
SecTor '09 - When Web 2.0 Attacks!
HoneyPy & HoneyDB (LASCON 2016)
Hacker halted2
Meetup 6/3/2017 - Artificiële Intelligentie: over chatbots & robots
Its the app stupid - CloudStack 2014 Collaboration Conference #CCNA14
Practical exploitation and social engineering
Teaching Elephants to Dance (Federal Audience): A Developer's Journey to Digi...
Attacker Ghost Stories - ShmooCon 2014
Strategies for securing your banks & enterprises (from someone who robs bank...
hacking into computer systems - a beginners guid
Oscon 2008 Open Micro Blogging Presentation
Hacking For Innovation
Web Application Hacking
Secular Technological Tailwinds
Von JavaEE auf Microservice in 6 Monaten - The Good, the Bad, and the wtfs...
Ad

Recently uploaded (20)

PPTX
operations management : demand supply ch
PPTX
TRAINNING, DEVELOPMENT AND APPRAISAL.pptx
PPTX
Board-Reporting-Package-by-Umbrex-5-23-23.pptx
DOCX
Handbook of Entrepreneurship- Chapter 5: Identifying business opportunity.docx
PDF
Daniels 2024 Inclusive, Sustainable Development
DOCX
80 DE ÔN VÀO 10 NĂM 2023vhkkkjjhhhhjjjj
DOCX
Hand book of Entrepreneurship 4 Chapters.docx
PDF
Environmental Law Communication: Strategies for Advocacy (www.kiu.ac.ug)
PPTX
2 - Self & Personality 587689213yiuedhwejbmansbeakjrk
PPTX
Slide gioi thieu VietinBank Quy 2 - 2025
PDF
Charisse Litchman: A Maverick Making Neurological Care More Accessible
PPTX
chapter 2 entrepreneurship full lecture ppt
PPTX
IITM - FINAL Option - 01 - 12.08.25.pptx
PDF
TyAnn Osborn: A Visionary Leader Shaping Corporate Workforce Dynamics
PDF
NISM Series V-A MFD Workbook v December 2024.khhhjtgvwevoypdnew one must use ...
PDF
Kishore Vora - Best CFO in India to watch in 2025.pdf
PPTX
basic introduction to research chapter 1.pptx
PPTX
Project Management_ SMART Projects Class.pptx
PPTX
CTG - Business Update 2Q2025 & 6M2025.pptx
PDF
Nante Industrial Plug Factory: Engineering Quality for Modern Power Applications
operations management : demand supply ch
TRAINNING, DEVELOPMENT AND APPRAISAL.pptx
Board-Reporting-Package-by-Umbrex-5-23-23.pptx
Handbook of Entrepreneurship- Chapter 5: Identifying business opportunity.docx
Daniels 2024 Inclusive, Sustainable Development
80 DE ÔN VÀO 10 NĂM 2023vhkkkjjhhhhjjjj
Hand book of Entrepreneurship 4 Chapters.docx
Environmental Law Communication: Strategies for Advocacy (www.kiu.ac.ug)
2 - Self & Personality 587689213yiuedhwejbmansbeakjrk
Slide gioi thieu VietinBank Quy 2 - 2025
Charisse Litchman: A Maverick Making Neurological Care More Accessible
chapter 2 entrepreneurship full lecture ppt
IITM - FINAL Option - 01 - 12.08.25.pptx
TyAnn Osborn: A Visionary Leader Shaping Corporate Workforce Dynamics
NISM Series V-A MFD Workbook v December 2024.khhhjtgvwevoypdnew one must use ...
Kishore Vora - Best CFO in India to watch in 2025.pdf
basic introduction to research chapter 1.pptx
Project Management_ SMART Projects Class.pptx
CTG - Business Update 2Q2025 & 6M2025.pptx
Nante Industrial Plug Factory: Engineering Quality for Modern Power Applications
Ad

GNUCITIZEN Pdp Owasp Usa 2007