Down the Rabbit Hole - A Journey Towards a Weakness in Chrome and a New Hacking Technique
Offered By: Hack in Paris via YouTube
Course Description
Overview
Embark on a captivating 36-minute conference talk from Hack in Paris that unveils a groundbreaking journey into web security vulnerabilities. Follow Gil Cohen, an experienced application security expert, as he delves into how a simple CRLF injection vulnerability led to the discovery of a new weakness in Chrome and other browsers, as well as a novel XSS-like hacking technique. Explore the concept of Frontend server hijacking, or "Frontjacking," which combines CRLF injection, poorly configured servers, and shared hosting to bypass existing security defenses such as CSP, HttpOnly cookie attributes, WAFs, CORS, and HTTPS. Gain insights into this innovative attack method that allows execution of reflected XSS and phishing-related payloads, potentially revolutionizing the field of web application security.
Syllabus
Down the rabbit hole: a journey towards a weakness in chrome & a new hacking technique by Gil COHEN
Taught by
Hack in Paris
Related Courses
MongoDB for .NET DevelopersMongoDB University Web Application Development – Capstone Course
University of New Mexico via Coursera Ciberseguridad: ataques y contramedidas
Universidad Rey Juan Carlos via Independent Reliable Cloud Infrastructure: Design and Process auf Deutsch
Google Cloud via Coursera Securing and Integrating Components of your Application 日本語版
Google Cloud via Coursera