Videos

Published on November 4th, 2016 📆 | 8273 Views ⚑

0

PHV 2016, "How to Find 1,352 WordPress XSS Plugin Vulnerabilities…." by Larry Cashdollar


iSpeech


"How to Find 1,352 WordPress XSS Plugin Vulnerabilities in 1 Hour (not really)" by Larry Cashdollar

I'll discuss my methodology in attempting to download all 50,000 WordPress plugins, automated vulnerability discovery, automated proof of concept creation and automated proof of concept verification. I'll go into where I went wrong, what I'd change and where I succeeded.





Larry W. Cashdollar (Twitter: @_larry0) has been working in the security field and finding vulnerabilities for over 15 years. With over 100 CVEs to his name, he is a known researcher in the field. You can see many of the disclosed vulnerabilities at vapidlabs.com. He is a member of the SIRT at Akamai Technologies.


2016-11-03 23:29:42

source

Tagged with:



Comments are closed.