libinjection: from sqli to xss - Nick Galbreath
1,881 views · Published 3 February 2014 · 34:16 · Indexed 5 October 2026
Channel: OWASP Foundation · 2014 · Science & Technology
libinjection was introduced at Black Hat USA 2012 to quickly and accurately detect SQLi attacks from user inputs. Two years later the algorithm has been used by a number of open-source and proprietary WAFs and honeypots. This talk will introduce a new algorithm for detecting XSS attacks. Like the SQLi libinjection algorithm, this does not use regular expressions, is very fast, and has a low false positive rate. Also like the original libinjection algorithm, this is available on GitHub with free license. We'll discuss the current state of libinjection SQLi, how SQLi and XSS differ semantically from an defenders point of view, how the libinjection algorithm works, the current results and availability. - Managed by the official OWASP Media Project https://www.owasp.org/index.php/OWASP_Media_Project
More from this channel
-
45:50
Revenge of the Geeks: Hacking Fantasy Sports Sites - Dan Kuykendall
-
51:38
Application Security at DevOps Speed and portfolio scale - Jeff Williams
-
35:56
HTML5 JS Security - maty siman
-
44:33
CSRF: not all defenses are created equal - Ari Elias-Bachrach
-
46:05
Next Generation Red Teaming - Robert Wood
-
44:28
Privacy vs Security Intricacies - Robert Hansen (keynote)
-
17:39
detecting and defending against state actor surveillance: robert r
-
50:12
OWASP Global Webinar - OWASP HIVE Project - Welcome to the Grid