YoVDO

Automated Account Takeover - The Rise of Single Request Attacks

Offered By: OWASP Foundation via YouTube

Tags

Conference Talks Courses Web Development Courses Cybersecurity Courses

Course Description

Overview

Explore the rise of single request attacks in account takeovers through this 49-minute conference talk from AppSecCali 2019. Delve into real-world case studies showcasing how attackers scale automated account takeovers using sophisticated techniques like headless browsers, JavaScript execution, and dynamic fingerprinting. Examine the limitations of traditional mitigation strategies and understand the growing incentives for attackers across various industries. Learn about tested pathways for preventing and mitigating single request attacks, and gain insights from Kevin Gosschalk, Founder and CEO of Arkose Labs, on distinguishing between computers and humans on the Internet. Cover topics including eye nerve mapping, the Kinect, fingerprinting, ITIN telemetry, photo image challenges, and specific examples from industries such as ticketing, gift cards, and credit cards.

Syllabus

Intro
Eye Nerve Mapping
The Kinect
Single Request Attacks
Account Takeover
Have I IB
What about the fingerprint
ITIN telemetry
Recapture
Photo Image Challenge
Single Request Attack Example
Who is ACDC
Ticket Inventory
Ticketnet
Gift Cards
Credit Cards
Story Time
The Software
Pokemon Go
Death Master File
How do we stop ATO


Taught by

OWASP Foundation

Related Courses

Software as a Service
University of California, Berkeley via Coursera
Intro to Computer Science
University of Virginia via Udacity
Web Development
Udacity
Software Engineering for SaaS
University of California, Berkeley via Coursera
CS50's Introduction to Computer Science
Harvard University via edX