When TLS Hacks You

  Рет қаралды 2,917

Black Hat

Black Hat

Күн бұрын

Lots of people try to attack the security of TLS. But, what if we use TLS to attack other things? It's a huge standard, and it turns out that features intended to make TLS fast have also made it useful as an attack vector.
Among other things, these features provide a lot of flexibility for Server-Side Request Forgery (SSRF). While past work using HTTPS URLs in SSRF has relied upon platform-specific bugs such as SNI injection, we can go further. In this talk, I present a novel, cross-platform way of leveraging TLS to target internal services.
By Joshua Maddux
Full Abstract & Presentation Materials: www.blackhat.c...

Пікірлер
TLS Handshake Explained - Computerphile
16:59
Computerphile
Рет қаралды 578 М.
7 Cryptography Concepts EVERY Developer Should Know
11:55
Fireship
Рет қаралды 1,4 МЛН
She made herself an ear of corn from his marmalade candies🌽🌽🌽
00:38
Valja & Maxim Family
Рет қаралды 18 МЛН
How to treat Acne💉
00:31
ISSEI / いっせい
Рет қаралды 108 МЛН
Solving a REAL investigation using OSINT
19:03
Gary Ruddell
Рет қаралды 234 М.
Transport Layer Security (TLS) - Computerphile
15:33
Computerphile
Рет қаралды 494 М.
I Spent 100 Hours Inside The Pyramids!
21:43
MrBeast
Рет қаралды 47 МЛН
Bugs of Yore: A Bug Hunting Journey on VMware's Hypervisor
39:16
Dear Game Developers, Stop Messing This Up!
22:19
Jonas Tyroller
Рет қаралды 820 М.
Cross-Site Request Forgery (CSRF) Explained
14:11
PwnFunction
Рет қаралды 479 М.
Running a Buffer Overflow Attack - Computerphile
17:30
Computerphile
Рет қаралды 2 МЛН
Coding a Web Server in 25 Lines - Computerphile
17:49
Computerphile
Рет қаралды 363 М.
She made herself an ear of corn from his marmalade candies🌽🌽🌽
00:38
Valja & Maxim Family
Рет қаралды 18 МЛН