cc cc . Earthquake attack ccc ccc . Sticker injection attack The - - PowerPoint PPT Presentation

cc
SMART_READER_LITE
LIVE PREVIEW

cc cc . Earthquake attack ccc ccc . Sticker injection attack The - - PowerPoint PPT Presentation

The day disaster struck the northeastern part of Japan ' or 1=1 -- Protect Y ourself c . SQL injection attack cc cc . Earthquake attack ccc ccc . Sticker injection attack The day disaster struck the northeastern part of Japan ' or 1=1 --


slide-1
SLIDE 1

The day disaster struck the northeastern part of Japan

' or 1=1 -- Protect Y

  • urself
  • c. SQL injection attack

cc

  • cc. Earthquake attack

ccc

  • ccc. Sticker injection attack
slide-2
SLIDE 2

The day disaster struck the northeastern part of Japan

' or 1=1 -- Protect Y

  • urself
  • c. SQL injection attack

cc

  • cc. Earthquake attack

ccc

  • ccc. Sticker injection attack
slide-3
SLIDE 3

3/22

c SQL injection attack against my Lightning Talks title!!

DAY1: Jun 13, 2011 Registration

slide-4
SLIDE 4

4/22

c SQL injection attack against my Lightning Talks title!!

DAY2: Jun 14, 2011 SQL injection attack !!

slide-5
SLIDE 5

5/22

c SQL injection attack against my Lightning Talks title!!

DAY3: Jun 15, 2011 SQL injection attack, too!!

; DROP TABLE ;

slide-6
SLIDE 6

6/22

c SQL injection attack against my Lightning Talks title!!

Countermeasure

Protect yourself

slide-7
SLIDE 7

7/22

c SQL injection attack against my Lightning Talks title!!

<bdo> stand for bidirectional override. How about this approach ?

slide-8
SLIDE 8

The day disaster struck the northeastern part of Japan

' or 1=1 -- Protect Y

  • urself
  • c. SQL injection attack

cc

  • cc. Earthquake attack

ccc

  • ccc. Sticker injection attack
slide-9
SLIDE 9

The day disaster struck the northeastern part of Japan

' or 1=1 -- Protect Y

  • urself
  • c. SQL injection attack

cc

  • cc. Earthquake attack

ccc

  • ccc. Sticker injection attack

Original 10 tips for earthquake safety http://www.tfd.metro.tokyo.jp/lfe/bou_topic/jisin/point10eng.htm

slide-10
SLIDE 10

10/22

Earthquake! Protect yourself first.

– Be careful and wait until the quake is over.

cc cc 6 tips for earthquake safety

d When You Feel An Earthquake

slide-11
SLIDE 11

11/22

Keep calm. Check all fire sources. Put out fire quickly.

– If you were using any sources of fire or heat, turn them off when the shaking calms down. – If a fire starts, put it out quickly and calmly.

cc cc 6 tips for earthquake safety

dd Right After An Earthquake

slide-12
SLIDE 12

12/22

Panic can hurt you.

– Be careful of fallen furniture and broken glass..

cc cc 6 tips for earthquake safety

ddd Right After An Earthquake

slide-13
SLIDE 13

13/22

Make sure you have a way out:

  • pen doors and windows.

– Secure an exit for escape when the shaking stops.

cc cc 6 tips for earthquake safety

dddd Right After An Earthquake

slide-14
SLIDE 14

14/22

Don't rush out in a panic. Watch out for falling objects.

– Watch out for falling

  • bjects such as

roof tiles, broken glass, and signs.

cc cc 6 tips for earthquake safety

ddddd Right After An Earthquake

slide-15
SLIDE 15

15/22

Keep away from gateposts and walls.

– If you feel an earthquake outside, stay away from concrete walls and other objects which may fall over.

cc cc 6 tips for earthquake safety

dddddd Right After An Earthquake

slide-16
SLIDE 16

16/22

Prepare for Earthquake

http://www.tfd.metro.tokyo.jp/eng/earthquakes.html

– 10 ways to prepare earthquake – 10 tips for earthquake safety

Tsunami Preparation

http://www.fdma.go.jp/en/tsunami/tsunami_en.html

cc cc 6 tips for earthquake safety Reference

slide-17
SLIDE 17

The day disaster struck the northeastern part of Japan

' or 1=1 -- Protect Y

  • urself
  • c. SQL injection attack

cc

  • cc. Earthquake attack

ccc

  • ccc. Sticker injection attack
slide-18
SLIDE 18

The day disaster struck the northeastern part of Japan

' or 1=1 -- Protect Y

  • urself
  • c. SQL injection attack

cc

  • cc. Earthquake attack

ccc

  • ccc. Sticker injection attack
slide-19
SLIDE 19

19/22

Overview Name badge is vulnerable to this issue. Impact Defaced name badge

ccc ccc Sticker injection attack (SIA) 7th Talking with all attendees

DoS (interruption in conversation)

slide-20
SLIDE 20

20/22

ccc ccc Sticker injection attack (SIA)

10 (v1.0) CVSS 77 (injection) CWE cpe:/a:first:namebadge:2011 CPE

slide-21
SLIDE 21

21/22

ccc ccc Sticker injection attack (SIA) Six variants

2nd project: Team Sticker 3rd project: E to & FIRST Stickers 4th project: FIRST Sticker 5th project: FIRST Sticker 1st project: none 6th project: Pikachu

slide-22
SLIDE 22

22/22

152 328 46.3%

17th Singapore

c

243 343 70.8%

18th Baltimore

cc cc

313 474 66.0%

19th Seville

ccc ccc

326 396 82.3%

20th Vancouver

cccc cccc

326 383 85.1

%

21th Kyoto

ccccc ccccc (^^;) (^^;) (^^;)

22th Miami

cccccc cccccc

23th Vienna

ccccccc ccccccc

Talked Total % 467

Jun 12, 2011 - Jun 17, 2011

c SIA in the wild c

ccc ccc Sticker injection attack (SIA) Statistics