YoVDO

Auditing the Compression Algorithm Weapon Cache

Offered By: Black Hat via YouTube

Tags

Black Hat Courses Cybersecurity Courses Application Security Courses Compression Algorithms Courses Vulnerability Testing Courses

Course Description

Overview

Explore the devastating potential of decompression bomb attacks in this Black Hat conference talk. Learn about the history, misconceptions, and various types of compression algorithm exploits, including zip bombs, image bombs, and HTTP bombs. Discover how to audit compression algorithms for vulnerabilities, understand the highest compression ratios, and identify the sloppiest parsers. Gain insights into creating a library of open-source tools for security researchers and developers to test application vulnerabilities. Examine real-world examples, including JPEG demos and browser crashes, and learn essential security measures such as limiting resources, request sizes, and compression ratios. Equip yourself with knowledge to guard against this often-overlooked but potentially catastrophic denial of service attack.

Syllabus

Introduction
Topics
About Me
What is a decompression bomb
JPEG demo
Preview crashes
History
Misconceptions
Silicon Valley
Zip Bomb
Zip Cache
Compression Ratio
Security 101
Image bombs
JPEG2000
ZapFly
PNG
Image Dimensions
Separate Workers
HTTP Bombs
Firefox
broadly
crash
zip
compression chart
limiting resources
limiting request sizes
limiting compression ratio
testing
burp image extension
bombedcodes
discussion


Taught by

Black Hat

Related Courses

Attack on Titan M, Reloaded - Vulnerability Research on a Modern Security Chip
Black Hat via YouTube
Attacks From a New Front Door in 4G & 5G Mobile Networks
Black Hat via YouTube
AAD Joined Machines - The New Lateral Movement
Black Hat via YouTube
Better Privacy Through Offense - How to Build a Privacy Red Team
Black Hat via YouTube
Whip the Whisperer - Simulating Side Channel Leakage
Black Hat via YouTube