YoVDO

Attacking Modern Web Technologies

Offered By: OWASP Foundation via YouTube

Tags

Conference Talks Courses Web Development Courses Cybersecurity Courses Amazon Web Services (AWS) Courses Ethical Hacking Courses Google Cloud Platform (GCP) Courses Slack Courses

Course Description

Overview

Dive into a comprehensive exploration of modern web technology vulnerabilities with top-ranked white-hat hacker Frans Rosén in this 43-minute conference talk from OWASP AppSec EU 2018. Discover methodologies for accessing private Slack tokens through postMessage and WebSocket-reconnect techniques, and learn how misconfigured AWS and Google Cloud settings can lead to full asset control by attackers. Gain insights into new hacks, bug bounty experiences, and eye-opening revelations about the true security of seemingly safe protocols and policies. Topics covered include AppCache, Dropbox upload policies, postmessage vulnerabilities, document service exploits, clientside race conditions, jQuery security issues, and more. Conclude with a Q&A session to deepen your understanding of cutting-edge web security challenges.

Syllabus

Introduction
Attacking Modern Web Technologies
About Frans Rosen
Outline of the talk
AppCache
Dropbox
Upload Policies
Custom Policies
Postmessage
Document Service
Clientside Race Conditions
Example
Speed Bumps
jQuery
What could I add to it
One more thing
Questions


Taught by

OWASP Foundation

Related Courses

Ethical Hacking
Indian Institute of Technology, Kharagpur via Swayam
Investigación en Informática Forense y Ciberderecho
University of Extremadura via Miríadax
MSc Cyber Security
Coventry University via FutureLearn
Network Security - Introduction to Network Security
New York University (NYU) via edX
Network Security - Advanced Topics
New York University (NYU) via edX