BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: SQL Injection Isn't Dead: Smuggling Queries at the P
 rotocol\n   Level\n   When: Saturday\, Aug 10\, 14:00 - 14:45 PDT\n   Wher
 e: LVCC West/Floor 1/Hall 1/Track 1 - [1]Map\n\n   Description:\n\n   SQL 
 injections seem to be a solved problem\; databases even have\n   built-in 
 support for prepared statements\, leaving no room for\n   injections. In t
 his session\, we will go a level deeper: instead of\n   attacking the quer
 y syntax\, we will explore smuggling attacks against\n   database wire pro
 tocols\, through which remote\, unauthenticated\n   attackers can inject e
 ntire (No)SQL statements into an application's\n   database connection.\n\
 n   Using vulnerable database driver libraries as case studies\, we will\n
    bring the concept of HTTP request smuggling to binary protocols. By\n  
  corrupting the boundaries between protocol messages\, we desynchronize\n 
   an application and its database\, allowing the insertion of malicious\n 
   messages that lead to authentication bypasses\, data leakage\, and\n   r
 emote code execution.\n\n   To put our findings into context\, we will exp
 lore the real-world\n   applicability of this new concept by comparing how
  robust various\n   languages and frameworks are against these attacks. We
  will also\n   discuss how smuggling attacks are not specific to database 
 wire\n   protocols but affect all kinds of binary protocols\, from databas
 es\n   over message queues to caching. We will end the session with\n   in
 spirations for future research to explore the topic further.\n\n     * [2]
 link\n\n     * [3]link\n\n     * [4]link\n\n     * [5]link\n\n     * [6]li
 nk\n\n     * [7]link\n\n     * [8]link\n\n   SpeakerBio:  Paul Gerste\, Vu
 lnerability Researcher\, R&D team at Sonar\n\n   Paul Gerste is a vulnerab
 ility researcher on Sonar's R&D team. He has\n   a proven talent for findi
 ng security issues\, demonstrated by his two\n   successful Pwn2Own partic
 ipations and discoveries in popular\n   applications like Proton Mail\, Vi
 sual Studio Code\, and Rocket.Chat.\n   When Paul is not at work\, he enjo
 ys playing CTFs with team FluxFingers\n   and organizing Hack.lu CTF.\n\n 
   '\n\n   1. #LVCCW_Level1_Hall1\n   2. https://www.postgresql.org/docs/cu
 rrent/protocol.html\n   3. https://dev.mysql.com/doc/dev/mysql-server/late
 st/PAGE_PROTOCOL.html\n   4. https://www.mongodb.com/docs/manual/reference
 /mongodb-wire-protocol/\n   5. https://redis.io/docs/latest/develop/refere
 nce/protocol-spec/\n   6. https://portswigger.net/research/http-desync-att
 acks-request-smuggling-reborn\n   7. https://portswigger.net/research/http
 2\n   8. https://portswigger.net/research/browser-powered-desync-attacks\n
 \n\n
DTEND:20240810T214500Z
DTSTART:20240810T210000Z
LOCATION:DC - LVCC West/Floor 1/Hall 1/Track 1
SUMMARY:SQL Injection Isn't Dead: Smuggling Queries at the Protocol Level
END:VEVENT
END:VCALENDAR
