Change 48743

Time Attribute with previous and current values
Change #48743
2018-05-14
04:31:51

create Calagator::Event 1250473733 Portland Java User Group (PJUG) - How to Protect against Deserialization Attacks Roll back

description nil <p>Insecure deserialization is one of the most critical web application security risks, yet it is by no means a new vulnerability category. Data serialization and deserialization have been used widely in applications, services and frameworks, with many programming languages supporting them natively. Deserialization got more attention recently as a potential vehicle to conduct several types of attacks: data tampering, authentication bypass, privilege escalation, various injections and, finally, remote code execution. Two recent vulnerabilities in Apache Commons and Apache Struts, both allowing remote code execution, helped raise awareness of this risk.</p> <p>We will discuss how data serialization and deserialization are used in software, the dangers of deserializing untrusted input, and how to avoid insecure deserialization vulnerabilities.</p> <p>Speaker:</p> <p>Alexei Kojenov (<a href="https://twitter.com/kojenov" class="linkified">https://twitter.com/kojenov</a>) is a Senior Application Security Consultant with years of prior software development experience. During his career with IBM, he gradually moved from writing code to breaking code. Since late 2016, Alexei has been working as a consultant at Aspect Security, helping businesses identify and fix vulnerabilities and design secure applications. Aspect Security was recently acquired by Ernst&Young and joined EY Advisory cybersecurity practice.</p>
end_time nil 2018-05-15 20:00:00 -0700
id nil 1250473733
source_id nil 996336525
start_time nil 2018-05-15 19:00:00 -0700
title nil Portland Java User Group (PJUG) - How to Protect against Deserialization Attacks
url nil https://www.meetup.com/PDXJUG/events/250603125/
venue_id nil 202395644