ISC StormCast for Wednesday, December 7th 2016
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 7 December 2016
⏱️ 7 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Wednesday, December 7th, 2016 edition of the Sandtonet Storm Center's |
| 0:06.6 | Stormcast. My name is Johannes Ulrich, and I'm recording from Jacksonville, Florida. |
| 0:12.4 | Many modern web applications are moving away from SQL databases to no sequel. We talked about this |
| 0:19.7 | a couple times in this podcast already, but |
| 0:23.6 | the one stack that gains some popularity here is the so-called mean stack, where mean stands |
| 0:31.6 | for MongoDB Express, Angularjs, and Node.js. The beauty of this is, from a developer point of view, |
| 0:39.6 | it's front end to back-end JavaScript. So really the only language you're coding in on the server |
| 0:46.3 | or on the client side is JavaScript. And then MongoDB will natively deal with JSON objects |
| 0:53.2 | very nicely. |
| 0:55.0 | So first question, of course, if we have no SQL, does this mean we have no SQL injection? |
| 1:01.2 | And actually, that's somewhat true. |
| 1:03.4 | In particular with MongoDB parameters don't really have to be escaped or like. |
| 1:09.5 | They're just passed to the database as a string. |
| 1:12.6 | So that works out pretty nicely. |
| 1:15.6 | However, the parameters themselves, they can be JSON objects. |
| 1:19.6 | And if you're not careful in assembling those JSON objects, |
| 1:24.6 | then of course you're back to what you had with secret injection. |
| 1:29.5 | Maybe not quite as bad, but a lot of the tricks that you're sort of used to with |
| 1:35.4 | secret injection are possible. |
| 1:38.4 | Boyan wrote some of this up in today's diary, and he walks through it in quite a bit of detail with examples. So if you're |
| 1:47.0 | testing MongoDB based applications, you definitely do want to take a look at his code samples |
| 1:54.0 | to see what's of the patterns are that you should log out for and how to write exploits in order to test whether or not your application |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

