YoVDO

Down the Rabbit Hole - A Journey Towards a Weakness in Chrome and a New Hacking Technique

Offered By: Hack in Paris via YouTube

Tags

Hack in Paris Courses Cybersecurity Courses Application Security Courses Reverse Proxies Courses

Course Description

Overview

Embark on a captivating 36-minute conference talk from Hack in Paris that unveils a groundbreaking journey into web security vulnerabilities. Follow Gil Cohen, an experienced application security expert, as he delves into how a simple CRLF injection vulnerability led to the discovery of a new weakness in Chrome and other browsers, as well as a novel XSS-like hacking technique. Explore the concept of Frontend server hijacking, or "Frontjacking," which combines CRLF injection, poorly configured servers, and shared hosting to bypass existing security defenses such as CSP, HttpOnly cookie attributes, WAFs, CORS, and HTTPS. Gain insights into this innovative attack method that allows execution of reflected XSS and phishing-related payloads, potentially revolutionizing the field of web application security.

Syllabus

Down the rabbit hole: a journey towards a weakness in chrome & a new hacking technique by Gil COHEN


Taught by

Hack in Paris

Related Courses

Computer Security
Stanford University via Coursera
Cryptography II
Stanford University via Coursera
Malicious Software and its Underground Economy: Two Sides to Every Story
University of London International Programmes via Coursera
Building an Information Risk Management Toolkit
University of Washington via Coursera
Introduction to Cybersecurity
National Cybersecurity Institute at Excelsior College via Canvas Network