Attack and defense: ASP.NET 2.0
The first session today started at 9AM, "Attack and Defense: Securing ASP.NET 2.0 Applications", held by Keith Brown.
The first talk was about general ASP.NET 2.0 security, not really as advanced as I'd hoped for, but still a good presentation. We got around some interesting SQL injection techniques, SQL truncation vulnerabilities, IO canonicalization and the awareness of user input in general.