Smashing the State Machine: The True Potential of Web Race Conditions

  Рет қаралды 2,479

Black Hat

Black Hat

4 ай бұрын

For too long, web race-condition attacks have focused on a tiny handful of scenarios. Their true potential has been masked thanks to tricky workflows, missing tooling, and simple network jitter hiding all but the most trivial, obvious examples. In this session, I'll introduce multiple new classes of race condition that go far beyond the limit-overrun exploits you're probably already familiar with.
Inside every website lurks a state machine: a delicately balanced system of states and transitions that each user, session, and object can flow through. I'll show how to fire salvos of conflicting inputs to make state machines collapse, enabling you to forge trusted data, misroute tokens, and mask backdoors. These exploits will be demonstrated across multiple high-profile websites, and a certain popular authentication framework....
By: James Kettle
Full Abstract and Presentation Materials: www.blackhat.com/us-23/briefi...

Пікірлер
How to prevent race conditions in a reservation system
6:34
Web Dev Cody
Рет қаралды 19 М.
顔面水槽をカラフルにしたらキモ過ぎたwwwww
00:59
はじめしゃちょー(hajime)
Рет қаралды 17 МЛН
OMG 😨 Era o tênis dela 🤬
00:19
Polar em português
Рет қаралды 9 МЛН
Ну Лилит))) прода в онк: завидные котики
00:51
FASTEST Way To Learn Coding and ACTUALLY Get A Job
10:44
Brian Cache
Рет қаралды 889 М.
the TRUTH about C++ (is it worth your time?)
3:17
Low Level Learning
Рет қаралды 588 М.
Something Rotten in the State of Data Centers
40:27
Black Hat
Рет қаралды 8 М.
Euler's formula with introductory group theory
24:28
3Blue1Brown
Рет қаралды 2,4 МЛН
A Worlds First On This Top Tier Radio - TIDRadio H3
11:52
Tech Minds
Рет қаралды 8 М.
My Invisible Adversary: Burnout
40:39
Black Hat
Рет қаралды 2,6 М.
顔面水槽をカラフルにしたらキモ過ぎたwwwww
00:59
はじめしゃちょー(hajime)
Рет қаралды 17 МЛН