YoVDO

Response Smuggling - Pwning HTTP/1.1 Connections

Offered By: Hack In The Box Security Conference via YouTube

Tags

Hack In The Box Security Conference Courses Reverse Engineering Courses Web Security Courses

Course Description

Overview

Explore advanced HTTP response smuggling techniques in this 55-minute conference talk from Hack In The Box Security Conference. Delve into a new approach focusing on response pipeline desynchronization, an unexplored attack vector in HTTP Smuggling. Discover a Desync variant exploiting a vulnerability in the HTTP protocol itself, reported under Google's Vulnerability Reward Program. Learn how to inject multiple messages at the backend server, hijack user sessions, and increase attack reliability. Examine the novel Response Scripting technique for creating custom malicious outbound messages using static responses. Watch a live demonstration showcasing how to gain control over two major ERP systems. Gain insights from security researcher Martin Doyhenard's expertise in Web security and reverse engineering, including his work on SAP and Oracle products.

Syllabus

Introduction
Agenda
What is Response Smuggling
Connection Headers
Exploits
Request Smuggling
Desynchronization
Synchronization Attack
Synchronization Attack Example
Demo
Cache Control Demo
In Real Systems
Video Demo
New Response
Conclusions
Questions


Taught by

Hack In The Box Security Conference

Related Courses

Internet History, Technology, and Security
University of Michigan via Coursera
Client-Server Communication
Google via Udacity
HTTP & Web Servers
Udacity
Network Security
Georgia Institute of Technology via Udacity
Web Security Fundamentals
KU Leuven University via edX