YoVDO

HTTP Desync Attacks - Smashing into the Cell Next Door

Offered By: Black Hat via YouTube

Tags

Black Hat Courses Web Development Courses Cybersecurity Courses Cache Poisoning Courses

Course Description

Overview

Explore advanced techniques for exploiting HTTP request isolation vulnerabilities in this Black Hat conference talk. Delve into HTTP desynchronization attacks that allow remote, unauthenticated attackers to manipulate web infrastructure, compromise visitor security, and exploit system weaknesses. Learn about the HTTP chain, desynchronization methods, detection strategies, and real-world case studies involving backend systems, cache poisoning, and CDNs. Examine specific examples, including attacks on PayPal's infrastructure, and witness a live demonstration. Gain insights into the underlying mechanisms of these attacks, their potential impact, and effective mitigation strategies to protect web applications from HTTP desync vulnerabilities.

Syllabus

Introduction
The HTTP Chain
Desynchronisation
Why does it work
Detection
Case Studies
Smuggling
Backend System
Cache Poisoning
CDNs
DOM
Local Feed
PayPal
PayPal Login
Demo
How to fix


Taught by

Black Hat

Related Courses

Practical HTTP Header Smuggling - Sneaking Past Reverse Proxies to Attack AWS and Beyond
Black Hat via YouTube
Web Cache Entanglement - Novel Pathways to Poisoning
Black Hat via YouTube
HTTP Desync Attacks - Request Smuggling Reborn
Black Hat via YouTube
Host of Troubles - Multiple Host Ambiguities in HTTP Implementations
Association for Computing Machinery (ACM) via YouTube
Request Smuggling 101
NorthSec via YouTube