YoVDO

SSRF PWNs - New Techniques and Stories

Offered By: Hack In The Box Security Conference via YouTube

Tags

Hack In The Box Security Conference Courses Network Security Courses Operating Systems Courses Server-Side Request Forgery (SSRF) Courses Web Application Security Courses Memcached Courses

Course Description

Overview

Explore advanced Server-Side Request Forgery (SSRF) techniques and real-world exploitation stories in this 48-minute conference talk from the Hack In The Box Security Conference. Delve into new attack vectors, including memcached and PHP FastCGI exploits, and learn how to leverage SSRF for direct socket communication with various applications. Discover expanded protocol usage beyond standard network libraries and gain insights from a comprehensive SSRF cheatsheet. Examine case studies of SSRF-related vulnerabilities in major platforms, with a focus on exploits targeting Yandex, a leading Russian Internet company. Gain valuable knowledge on web application security, network perimeter bypassing, and cutting-edge SSRF attack methodologies from security experts Vladimir Vorontsov and Alexander Golovko.

Syllabus

Introduction
Previous techniques
Simple spoofing attacks
Reflection attack
Reflection attacks
TCP Fast Open
TCP Security Limitations
ARP Version 6
TCP First Open Concept Attack
Link Local Addresses
IP Version 6
Protocols
Which server is most secure
SSL Validator
Main Schema
yandex bug bounty
results
questions


Taught by

Hack In The Box Security Conference

Related Courses

OWASP Top 10 - A10:2021 - Server-Side Request Forgery (SSRF)
Cybrary
Popular Web Attacks - XSS, CSRF, SSRF, SQL Injection, MIME Sniffing, Smuggling and More
Hussein Nasser via YouTube
API-Induced SSRF - How Apple Pay Scattered Vulnerabilities Across the Web
Black Hat via YouTube
A New Era of SSRF - Exploiting URL Parser in Trending Programming Languages
Black Hat via YouTube
Piercing the Veil - Server Side Request Forgery Attacks on Internal Networks
Cooper via YouTube