DEF CON 14 - Yuan Fan - MatriXay: When Web App & Database Security Pen-Test/Audit Is a Joy
173 views · Published 5 February 2014 · 29:12 · Indexed 1 October 2026
Channel: DEFCONConference · 2014 · Science & Technology
Yuan Fan - MatriXay: When Web App & Database Security Pen-Test/Audit Is a Joy "This topic will present a new web-app/DB pen-test tool. This tool supports both proxy (passive) mode as well as direct URL targeting. It is a mixed Web App SQL Injection systematic pen-test and WebApp/Database scanner/auditing-style tool and supports most popular databases used by web applications such as Oracle, SQL Server, Access and DB2. It has many unique features from web app backend Database automatic detection to the ability to browse database objects (without the need to ask for a passwords, of course), to the ability to locate/search for any sensitive content inside the DB and find more vulnerability points from source as well as privilege escalation.'''---""" Bio: Yuan Fan, GCIH, GCIA, CISSP, is the founder of DBAppSecurity Inc with consulting service on enterprise security management especially on database and application security. His expertise spans from network layer to application/database layer Security. Before that he worked 5+ years for ArcSight for a variety of security device?s connectors, and many years in network management area. He holds a Master of Computer engineering degree from San Jose State University. Last year, he presented the abnormal detection between webApp layer and DB layer. This time he is going to show the brand new sword out for the first time. The tool?MatriXray?was designed and developed by him and his partner XiaoRong in their spare (night) time is deemed to be promising from several aspects including the deep pen-test ability framework and cross database support (currently supports Oracle, SQL Server, DB2,Access).
More from this channel
-
7:53
DEF CON 20 Documentary Bonus Clips - CDC muxed
-
3:45
DEF CON 20 Documentary Bonus Clips - Not the Same Anymore
-
2:39
DEF CON 20 Documentary Bonus Clips - Barkode and Bloodkode
-
47:43
DEF CON 20 - Raphael Mudge - Cortana: Rise of the Automated Red Team
-
43:15
DEF CON 20 - Peter Hannay - Exchanging Demands
-
49:37
DEF CON 20 - Richard Thieme - Twenty Years Back Twenty Years Ahead
-
25:01
DEF CON 20 - Ryan Holeman - Passive Bluetooth Monitoring in Scapy
-
48:14
DEF CON 20 - Xeno Kovah and Corey Kallenberg - No More Hooks