Browser-Powered Desync Attacks: A New Frontier in HTTP Request Smuggling

  Рет қаралды 4,049

Black Hat

Black Hat

Күн бұрын

...In this session, I'll show you how to turn your victim's web browser into a desync delivery platform, shifting the request smuggling frontier by exposing single-server websites and internal networks. You'll learn how to combine cross-domain requests with server flaws to poison browser connection pools, install backdoors, and release desync worms....
By: James Kettle
Full Abstract & Presentation Materials: www.blackhat.c...

Пікірлер
HTTP Request Smuggling - False Positives
16:40
PinkDraconian
Рет қаралды 13 М.
It’s all not real
00:15
V.A. show / Магика
Рет қаралды 20 МЛН
Don’t Choose The Wrong Box 😱
00:41
Topper Guild
Рет қаралды 62 МЛН
coco在求救? #小丑 #天使 #shorts
00:29
好人小丑
Рет қаралды 120 МЛН
Client-side desync vulnerabilities - a breakthrough in request smuggling techniques
12:51
Bug Bounty Reports Explained
Рет қаралды 17 М.
We are Overland AI
1:40
Overland AI
Рет қаралды 49 М.
HTTP Desync Attack Explained With Paper
13:00
LiveUnderflow
Рет қаралды 14 М.
Missing HTTP Security Headers - Bug Bounty Tips
15:48
LiveOverflow
Рет қаралды 143 М.
Android App Bug Bounty Secrets
20:14
LiveOverflow
Рет қаралды 106 М.
HTTP Desync Attacks: Request Smuggling Reborn
47:36
Black Hat
Рет қаралды 30 М.