BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//cfp.hackfest.ca//hackfest-2020//speaker//C3H9UL
BEGIN:VTIMEZONE
TZID:EST
BEGIN:STANDARD
DTSTART:20001029T030000
RRULE:FREQ=YEARLY;BYDAY=-1SU;BYMONTH=10;UNTIL=20061029T070000Z
TZNAME:EST
TZOFFSETFROM:-0400
TZOFFSETTO:-0500
END:STANDARD
BEGIN:STANDARD
DTSTART:20071104T030000
RRULE:FREQ=YEARLY;BYDAY=1SU;BYMONTH=11
TZNAME:EST
TZOFFSETFROM:-0400
TZOFFSETTO:-0500
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20000402T030000
RRULE:FREQ=YEARLY;BYDAY=1SU;BYMONTH=4;UNTIL=20060402T080000Z
TZNAME:EDT
TZOFFSETFROM:-0500
TZOFFSETTO:-0400
END:DAYLIGHT
BEGIN:DAYLIGHT
DTSTART:20070311T030000
RRULE:FREQ=YEARLY;BYDAY=2SU;BYMONTH=3
TZNAME:EDT
TZOFFSETFROM:-0500
TZOFFSETTO:-0400
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
UID:pretalx-hackfest-2020-NSUM8E@cfp.hackfest.ca
DTSTART;TZID=EST:20201121T173000
DTEND;TZID=EST:20201121T182000
DESCRIPTION:This presentation will focus on private and new optimized SQL i
 njection exploitation methods.\n\nNew private tools that exploit Blind SQL
  Injection vulnerabilities will be released. These ones are much more fast
 er than the existing free and commercial tools\nout there because the priv
 ate ones use modern attack vectors (created by myself) which perform cleve
 r injections designed to hack databases in more efficient methods.\n\nTo e
 xplain this\, graphs and tables will be used to show the differences betwe
 en the best tools out there and the 3 private tools introduced in the talk
 .\n\nAll the techniques used by the tools\, which are the result of origin
 al private research\, will be exposed in high detail.\n\nThe most popular 
 free tool to exploit SQL Injections\, sqlmap\, needs to make a maximum of 
 7 requests to retrieve a single character and it also has threading\nlimit
 ations. There is a notable gap between sqlmap and my new tools because the
 y only require a maximum of 3 requests to retrieve a character. They\nare 
 also finer not only because of the number of requests they require nor due
  to the threading capabilities they have\, but also because the SQL inject
 ion itself runs much faster faster due to the instruction set they use.\n\
 nUnderground methods (some discovered by a fellow 1337 researcher and othe
 rs by me) to test for SQL Injection and XSS vulnerabilities will be shown.
  These will transform pen-testing into an easier and more optimized task.
DTSTAMP:20260815T123656Z
LOCATION:Hackfest - Track 1
SUMMARY:Lightspeed SQL Injections - Ruben Ventura
URL:https://cfp.hackfest.ca/hackfest-2020/talk/NSUM8E/
END:VEVENT
END:VCALENDAR
