YoVDO

Httpillage - Calling All Nodes

Offered By: LASCON via YouTube

Tags

LASCON Courses Penetration Testing Courses Dictionary Attacks Courses

Course Description

Overview

Explore the world of distributed HTTP-based attacks in this 40-minute LASCON conference talk. Learn about Httpillage, a tool designed to distribute attacks across multiple nodes, simulating real-world threats more effectively than single-host attacks. Discover how to conduct online password brute-force attempts, denial of service attacks, and application enumeration with increased speed and effectiveness. Follow along with live demonstrations of common attacks across multiple nodes, including brute-forcing time-based password reset tokens. Gain insights into providing proper impact demonstrations during penetration testing, and understand the limitations of traditional single-host approaches. Delve into topics such as username enumeration, job response flags, dictionary attacks, status codes, and weak token exploitation. Enhance your understanding of application security testing and learn how to better model real-world threats in your assessments.

Syllabus

Intro
Penetration Tester vs Vulnerability Assessment
HTTP Pillage
Username Enumeration
Live Demo
Edit Job
Response Flag
Dictionary
Squiggly Bracket
Status codes
Spinning up another node
Thread count
Result
Local hosting
Search tip
verbose error message
Increasing exploitability
Expired tokens
Django envy
Forgot password mechanism
Character sets
Password reset
Weak tokens
Denial of service
Outro


Taught by

LASCON

Related Courses

Everything Useful I Learned About Software Security, I Learned at Microsoft
LASCON via YouTube
How I Met Your Girlfriend
LASCON via YouTube
HTTPS Can Byte Me
LASCON via YouTube
Why Does Bad Software Happen to Good People
LASCON via YouTube
Mitigating Business Risks with Application Security
LASCON via YouTube