YoVDO

Attacking Modern Web Technologies

Offered By: NDC Conferences via YouTube

Tags

NDC Conferences Courses Web Development Courses Cybersecurity Courses Cloud Computing Courses Amazon Web Services (AWS) Courses Ethical Hacking Courses Google Cloud Platform (GCP) Courses

Course Description

Overview

Save Big on Coursera Plus. 7,000+ courses at $160 off. Limited Time Only!
Explore modern web technology vulnerabilities and hacking techniques in this 55-minute conference talk by top-ranked white-hat hacker Frans Rosén. Discover how to access private Slack tokens using postMessage and WebSocket-reconnect, and learn about vulnerable configurations in AWS and Google Cloud that can lead to full asset control. Gain insights into new hacks, bug bounty stories, and eye-opening revelations about the security of protocols and policies you thought were safe. Dive into topics such as the Werkzeug Debugger, Patreon vulnerabilities, cookie stuffing, browser bugs, AppCache demos, Service Workers, AWS S3 upload policies, and Slack's postMessage function. Walk away with a deeper understanding of web security challenges and the importance of robust protection measures in today's digital landscape.

Syllabus

Intro
Frans Rosén
How did I get here?
Rundown
Werkzeug Debugger
Patreon
Cookie Stuffing
Bug in EVERY BROWSER
Surprise - Specification was vague
AppCache DEMO
Service Workers - AppCache's bigger brother
Upload Policies AWS S3
Pitfalls AWS S3
AWS STS • Generates temporary credentials client side
Your own policy-logic - The worst
Full read access to every object
Slack's postMessage
Slack's call function
Rabbit hole
reconnect!
Walkthrough


Taught by

NDC Conferences

Related Courses

Communicating Data Science Results
University of Washington via Coursera
Cloud Computing Applications, Part 2: Big Data and Applications in the Cloud
University of Illinois at Urbana-Champaign via Coursera
Cloud Computing Infrastructure
University System of Maryland via edX
Google Cloud Platform for AWS Professionals
Google via Coursera
Introduction to Apache Spark and AWS
University of London International Programmes via Coursera