YoVDO

Million Browser Botnet

Offered By: LASCON via YouTube

Tags

LASCON Courses Cybersecurity Courses Javascript Courses Cross-Site Request Forgery (CSRF) Courses HTML5 Courses Password Cracking Courses DDoS Attacks Courses

Course Description

Overview

Explore the dark potential of online advertising networks in this eye-opening LASCON conference talk. Discover how easily attackers can create massive JavaScript-driven browser botnets for pennies, leveraging ad networks to distribute malicious code at scale. Learn about the various attack vectors, including DDoS, email spam campaigns, hash cracking, and password brute-forcing, all achievable through simple HTML5 and JavaScript. Understand the power of Cross-Site Request Forgery (CSRF) attacks that require no zero-days or malware, leaving no traces behind. Examine the evolution of web attack methods and why advertising networks present a uniquely scalable and invisible threat. Dive into topics such as JavaScript malware, de-anonymization, intranet hacking, web workers, and distributed services. Witness live demonstrations of botnet creation and control, and grasp the implications of this easily accessible attack vector for web security.

Syllabus

Introduction
JavaScript Malware
CSRF
De Anonymize
intranet packing
web workers
distributed to service
demo
distribution
ad networks
browser time networks
ad network
admin panel
ad
concurrent connections
Akamai
Results


Taught by

LASCON

Related Courses

Comparing WAF and RASP - Why?
LASCON via YouTube
API Security - Is it the New Application Attack Surface and How to Secure at Enterprise Scale
LASCON via YouTube
Privacy Impact Assessments - How Much Privacy Is Enough?
LASCON via YouTube
Your Frontier Defense - Understanding Web Application Firewalls
LASCON via YouTube
Doing This One Crazy Thing Will Change Your AppSec Program Forever
LASCON via YouTube