YoVDO

Everybody Wants SOME - Advance Same Origin Method Execution

Offered By: Hack In The Box Security Conference via YouTube

Tags

Hack In The Box Security Conference Courses Reverse Engineering Courses Cross-Site Scripting (XSS) Courses Web Application Security Courses

Course Description

Overview

Explore the advanced aspects of Same Origin Method Execution (SOME), a powerful web attack technique, in this 55-minute conference talk from the Hack In The Box Security Conference. Delve into how SOME exploits callback endpoints to perform unintended actions on websites, bypassing common security measures. Examine real-world case studies of SOME attacks against major platforms like WordPress, Google, PayPal, and Microsoft. Learn how SOME can enable XSS attacks in previously secure environments. Understand the differences between SOME and JSONP, and discover a new approach to user interaction in SOME attacks. Gain insights from Ben Hayak, an experienced Information Security Engineer and researcher, on how seemingly innocuous callback endpoints can become backdoors in even the most protected domains, potentially causing severe damage to web applications.

Syllabus

#HITB2017AMS D2T1 - Everybody Wants SOME: Advance Same Origin Method Execution - Ben Hayak


Taught by

Hack In The Box Security Conference

Related Courses

Browser Hacking With ANGLE
Hack In The Box Security Conference via YouTube
Can A Fuzzer Match A Human
Hack In The Box Security Conference via YouTube
Biometrics System Hacking in the Age of the Smart Vehicle
Hack In The Box Security Conference via YouTube
ICEFALL - Revisiting A Decade Of OT Insecure-By-Design Practices
Hack In The Box Security Conference via YouTube
Fuzzing the MCU of Connected Vehicles for Security and Safety
Hack In The Box Security Conference via YouTube