YoVDO

Cracking the Lens - Targeting HTTP's Hidden Attack-Surface

Offered By: Black Hat via YouTube

Tags

Black Hat Courses Penetration Testing Courses Web Security Courses Exploit Development Courses

Course Description

Overview

Explore the hidden attack surface of modern websites in this 44-minute Black Hat conference talk. Delve into the often-overlooked vulnerabilities within transparent systems designed to enhance performance, extract analytics, and provide additional services. Learn about exploiting collaboration features, chaining proxy servers, and leveraging off-the-shelf exploits. Discover techniques for targeting internal networks, extracting profile headers, and utilizing refer headers. Gain insights into reverse proxy fetching, collaboration vulnerabilities, and replication methods. Understand prevention strategies and walk away with a comprehensive summary of this critical aspect of web security.

Syllabus

Introduction
Trace Routes
Outline
Collab Everywhere
Who Did I Target
Exploits
Impact
Chaining Proxy Servers
New Relic Internal Network
GlobalEEKS
Exploiting Helpers
Extract Profile Header
Refer Header
Offtheshelf exploits
What else can you do
Hack Ability
Final Exploit
Reverse Proxy Fetch
Collaborate
Facebook
Collaboration Everywhere
Replication
Prevention
Summary


Taught by

Black Hat

Related Courses

Network Security
Georgia Institute of Technology via Udacity
Proactive Computer Security
University of Colorado System via Coursera
Identifying, Monitoring, and Analyzing Risk and Incident Response and Recovery
(ISC)² via Coursera
Hacker101
HackerOne via Independent
CNIT 127: Exploit Development
CNIT - City College of San Francisco via Independent