YoVDO

HTML5 Top 10 Threats - Stealth Attacks & Silent Exploits

Offered By: Black Hat via YouTube

Tags

Black Hat Courses Web Development Courses Cybersecurity Courses Vulnerability Scanning Courses

Course Description

Overview

Explore the emerging security challenges posed by HTML5 in this comprehensive Black Hat USA 2012 conference talk. Delve into the enhanced browser capabilities and Rich Internet Application features of HTML5, including its implementation on mobile devices. Examine the complex technology stack comprising XMLHttpRequest, Document Object Model, Cross Origin Resource Sharing, and advanced HTML/Browser rendering. Discover new browser technologies such as localstorage, webSQL, websocket, and webworkers, which expand the attack surface for malicious actors. Learn about the top 10 HTML5 threats, including CORS attacks, ClickJacking, XSS vulnerabilities, web storage exploitation, SQL injection, web messaging injections, DOM-based attacks, third-party widget risks, WebSocket vulnerabilities, and protocol/schema/API attacks. Gain insights into stealth attack techniques and silent exploits that are difficult to detect yet highly effective in compromising systems. Understand the importance of addressing these new attack vectors in today's cybersecurity landscape and explore emerging tools and techniques for HTML5 vulnerability scanning.

Syllabus

Black Hat USA 2012 - HTML5 Top 10 Threats: Stealth Attacks & Silent Exploits


Taught by

Black Hat

Related Courses

Attack on Titan M, Reloaded - Vulnerability Research on a Modern Security Chip
Black Hat via YouTube
Attacks From a New Front Door in 4G & 5G Mobile Networks
Black Hat via YouTube
AAD Joined Machines - The New Lateral Movement
Black Hat via YouTube
Better Privacy Through Offense - How to Build a Privacy Red Team
Black Hat via YouTube
Whip the Whisperer - Simulating Side Channel Leakage
Black Hat via YouTube