Рет қаралды 22,405
Recorded live on January 19, 2019 at LevelUp 0x03.
Learn more: www.bugcrowd.com/resources/ev...
Join Bugcrowd: bit.ly/invitesplz
Have a question related to this talk? Post it on our forum: forum.bugcrowd.com/t/levelup-...
Abstract:
"Automated web application attacks are terminally limited by the number of HTTP requests they can send. It's impossible to know how many hacks have gone off the rails because you didn't quite manage to bruteforce a password, missed a race condition, or failed to find a crucial folder.
In this session I'll introduce, demo and distribute Turbo Intruder - a research grade Burp extension built from scratch with speed in mind. Most tools struggle to reach 1,000 HTTPS requests per second (RPS), whereas Turbo Intruder uses a selection of custom HTTP stacks to exceed 30,000 RPS while minimising the chance of your router exploding. It's also designed to be fully extensible so you can easily launch multi-step attacks and filter responses.
As well as showing how to use the tool, I'll discuss the underlying HTTP abuse that enables it to go so fast, so you can attain similar speeds in any tools you happen to write. Finally, I'll cover some new research I'm currently pursuing on generating context-aware payloads and automatically identifying interesting responses."
Follow us on Twitter: / bugcrowd