YoVDO

Dangling Packages Leading to RCE

Offered By: nullcon via YouTube

Tags

nullcon Courses Cybersecurity Courses Remote Code Execution (RCE) Courses JSON Courses Remote Code Execution Courses

Course Description

Overview

Explore dependency confusion attacks in this 30-minute webinar from nullcon. Discover how developers inadvertently leave non-standard node and Python packages in project JSON files, creating vulnerabilities that attackers can exploit. Learn how malicious actors can claim and publish these packages, leading to remote code execution when victims install them using standard procedures. Witness real-world proof of concepts and practical demonstrations of these attack vectors. Presented by Prasoon Gupta, an Application Security Engineer and Bug Bounty Hunter, this talk provides valuable insights into securing your development process against RCE threats stemming from dangling packages.

Syllabus

Dangling Packages leading to RCE | Prasoon Gupta | Nullcon Webinar 2021


Taught by

nullcon

Related Courses

BurpSuite Extensions
YouTube
Web Hacking - Técnicas de Invasão em Ambientes Web [Pentest]
Udemy
JavaScript Security
Infosec via Coursera
CVE Series: Log4J (CVE-2021-44228)
Cybrary
CVE-2021-44228 - Log4j - Minecraft Vulnerable and So Much More
John Hammond via YouTube