No video

albinowax - HTTP Desync Attacks: Smashing into the Cell Next Door - DEF CON 27 Conference

  Рет қаралды 53,045

DEFCONConference

DEFCONConference

Күн бұрын

Пікірлер: 27
@sakettestsakettest8009
@sakettestsakettest8009 4 жыл бұрын
Massive respect to him...this guy is a genius.
@6544441
@6544441 4 жыл бұрын
You can find the whitepaper, tool, and online labs at portswigger.net/research/http-desync-attacks-request-smuggling-reborn
@mo938
@mo938 2 жыл бұрын
@xXRedTheDragonXx
@xXRedTheDragonXx 3 жыл бұрын
This is legitimately one of the worst vulnerabilities ever discovered. Honestly, this should scare every developer, server host, backend developer, frontend developer, CDN developer, anyone who's software was exploited in the chain and every user on the internet. Being able to inject code to random users page with nothing but a few post requests is absolutely terrifying, and being able to steal plain-text creds is horrifying
@kof2002x
@kof2002x 4 жыл бұрын
honestly i like the researches of albinowax "Respect"
@ChadChad1776
@ChadChad1776 4 жыл бұрын
Scariest talk I've ever watched.
@BeggarsAreChoosers
@BeggarsAreChoosers 4 жыл бұрын
As always, outstanding research material by James (albinowax). This is such a big material by itself, I don't know how to understand every bit of this attack. Just checked that his blog on this attack is around 26 pages long with lots of other pointers and links. It's almost kind of a book. I don't know I will be able to understand fully as only a Genius like him can make this type of material and only a Genious will understand it fully. This might take my entire life to go through all research materials that he alone contributes every year. His name will be in the history of Ethical Hacking.
@0x1h0b
@0x1h0b 4 жыл бұрын
Man.. i love how good he explains.. huge respect sir..
@CropCircleSystems
@CropCircleSystems 4 жыл бұрын
Great exploits. I could smell this vulnerability almost as long as I can remember and it's just insane how long, far and wide it's still applicable after being documented over a decade ago. I never could have done and put together all this research and implemented such effective exploits. Thorough exploration of the problem space. Thorough documentation of cause and effect. GREAT presentation. My favorite from DEFCON 27. I was on the edge of my seat the entire time. On another note, I've been pronouncing the letter H wrong my entire life. Thank you so much for this albinowax!
@UsamaAli-kr2cw
@UsamaAli-kr2cw Жыл бұрын
This is mind blowing research done by james :)
@jpphoton
@jpphoton 23 күн бұрын
the vast domain space of http and a brilliant mind laying it down like Shakespeare extremely insightful thank you
@sveneFX
@sveneFX Жыл бұрын
Thx so much for sharing, this is insane - well done!
@nikivc
@nikivc 4 жыл бұрын
Super awesome, what a good talk !
@KristyLeeDeTert-qr3yb
@KristyLeeDeTert-qr3yb Ай бұрын
😊❤
@JuanBotes
@JuanBotes 2 жыл бұрын
Thanks for sharing your knowledge \o/
@KeithMakank3
@KeithMakank3 Жыл бұрын
Missed opertunity to call this a : Joiny Cache vulnerability
@DaveKupratis
@DaveKupratis 4 жыл бұрын
Very well done!
@FantubeChannel
@FantubeChannel 4 жыл бұрын
Awesome!
@steiner254
@steiner254 2 жыл бұрын
This is awesome!
@siddharthchhetry4218
@siddharthchhetry4218 3 жыл бұрын
Godly guy.
@gddaredevil
@gddaredevil Жыл бұрын
*_great_*
@iamkid4357
@iamkid4357 4 жыл бұрын
awesome
@5uSWEq7t
@5uSWEq7t 4 жыл бұрын
wizard class hacker
@alphawolf4446
@alphawolf4446 4 жыл бұрын
0 dislikes - that's my boy standard : )
@amithc9429
@amithc9429 4 жыл бұрын
😍😍😍
@TheIndiaView
@TheIndiaView 3 жыл бұрын
fucking awesome
@RyanLynch1
@RyanLynch1 4 жыл бұрын
wow I want to be that smart one day lol... then maybe I can get PayPal to give me 40k too haha
Gli occhiali da sole non mi hanno coperto! 😎
00:13
Senza Limiti
Рет қаралды 20 МЛН
Bill Swearingen - HAKC THE POLICE - DEF CON 27 Conference
41:18
DEFCONConference
Рет қаралды 610 М.
HTTP Desync Attacks: Request Smuggling Reborn
47:36
Black Hat
Рет қаралды 30 М.
DEF CON 29 - James Kettle -  HTTP2: The Sequel is Always Worse
40:04
DEFCONConference
Рет қаралды 18 М.
Philippe Laulheret - Intro to Hardware Hacking - DEF CON 27 Conference
46:07
Cracking the Lens: Targeting HTTP's Hidden Attack-Surface
44:06
HTTP Desync Attacks: Smashing Into The Cell Next Door - James Kettle
44:41
Watch me hack a Wordpress website..
28:52
Tech Raj
Рет қаралды 196 М.
Gli occhiali da sole non mi hanno coperto! 😎
00:13
Senza Limiti
Рет қаралды 20 МЛН