Hacking the SOA

Service-oriented-architectures are used by companies to integrate their IT infrastructure with customers, partners and employees in order to automate business process. But these SOAs are vulnerable to attacks that damage the confidentiality, integrity and availability of business-critical data. It is a common mistake to think that firewalls are enough to protect networked applications, but when using distributed components, web services and an enterprise service bus the firewall is useless. During this presentation we will discuss the threats that exist and how a hacker will attempt to exploit these threats. A hacker will focus on the different entrypoints in a SOA: web services, message queues, database storage and more. When he obtains access to an entrypoint, he can successfully manipulate XML messages to obtain confidential data, change sensitive information or destroy critical records. We will see the different attacks: message replay attacks, man-in-the-middle, authentication bypass, session hijacking, SQL Injection, Denial-of-Service,...

Erwin Geirnaert BIO

Ir. Erwin Geirnaert is partner and co-founder of ZION SECURITY, the European application security company. ZION SECURITY provides security services that span both testing and development. ZION SECURITY performs contract security testing of applications and helps customers to reproduce, triage and fix security vulnerabilities. ZION SECURITY's security services include training, threat modeling, data flow analysis, security design reviews, code reviews, feature development, bug fixing, test planning, test management and test execution. Ir. Geirnaert obtained a Master of Science in Computer Science from the University of Ghent. His affinity with Java, web services and security started at The Reference where he was responsible for the roll-out of J2EE and WebSphere as a full-blown development platform. He designed secure J2EE architectures for various clients and became an active member of the WebSphere User Group. After his J2EE adventure, he joined Ascure as an IT Security Technology Specialist, with a specialisation in application security. He is a certified WebSphere System Engineer, Certified Information Systems Security Professional and Certified Information Systems Auditor. Because he is a born enterpreneur he co-founded ZION SECURITY in 2005 where he is responsible for security testing projects for different organisations from government, finance and healthcare.

Related Links

(None)

Adaptavist Theme Builder Powered by Atlassian Confluence