ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Microsoft to lift lid on hacker conference

Tom Espiner ZDNet.co.uk

Published: 17 Mar 2006 16:55 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Microsoft is to publish the findings of its three day "Blue Hat 3" security conference, according to a blog posting by one of its organisers.

The third Blue Hat conference, which was held last week, was organised to discuss the current state of global security. Security researchers were invited to give talks and practical demonstrations to assembled Microsoft executives on topics such as "exploiting Web applications" and "hacking search engines".

"Over the coming days we'll be posting our reflections on BlueHat 3 as well as photos and links to podcasts and video from the event," wrote Kymberlee Price, a Microsoft security programme manager, on Thursday.

"We sincerely hope that our BlueHat 3 speakers (and BlueHat 1 & 2 speakers) will post their comments to the site as well and share their BlueHat experience with you," Price added.

Details of Blue Hat 3 will be published during the spring, according to TechNet, Microsoft's developer site.

"It was open and honest discussion about problems specific to Microsoft technologies and also problems that affect our entire industry," wrote conference organiser Brad Sarsfield, a Microsoft SQL Server coder in another BlueHat blog posting.

"Hearing senior executives say things like: 'I want the people responsible for those features in my office early next week; I want to get to the bottom of this,' was at least one measure of success from my point of view for the event," Sarsfield added.

The first day was a set of talks to senior product leadership and executives. The second day took a SQL, Data and Web application focus while the third day focused on the Windows platform, according to Sarsfield.

Security researcher and NGS co-founder David Litchfield gave a talk on Oracle database security at the event. Litchfield told ZDNet UK that various aspects of database security were discussed during his time at the conference.

"There were talks on SQL injection and database rootkits. SQL injection subverts the application logic, piggybacking attack queries on valid SQL queries. An attacker can then do something nasty like access user passwords and IDs," said Litchfield.

"SQL injection is probably today's biggest security issue. This problem has been known about for years, but seven out of ten Web applications are still vulnerable," Litchfield added. "I find it extremely frustrating."

Litchfield applauded Microsoft for holding the Blue Hat conference.

"I think it's great Microsoft are doing this. It's still investing so much into its security culture. Oracle could take a leaf out of their book." Litchfield has heavily criticised Oracle in the past, after he discovered a clutch of vulnerabilities in its database software.

Litchfield also told ZDNet UK that while attack code was demonstrated at Blue Hat 3, "no Microsoft issues were discussed" during his time at the conference.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
54 out of 154 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:















Related Jobs

IT Support Engineer (Terminal Services,AD,VMWare,Win Server 2003)

Exposure to HP Hardware & tools (HPSIM) is preferred & you will be the main IT contact in the London office responsible for queries arising locally ...

(CCVP/CCIE-Voice) Network Consultant, 60-80,000

This is an exciting role, which will see you involved in initial talks with customers to understand requirements and advise on the best solutions, ...

Terminal Services Specialist at Top Financial Comapny!(Wins/HP/AD)

As the main contact in the London office, you will be responsible for any queries arising locally from video conference issues to networking. Top ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment