Smashing the State Machine - The True Potential of Web Race Conditions
Offered By: nullcon via YouTube
Course Description
Overview
Explore the untapped potential of web race condition attacks in this conference talk from Nullcon Goa. Delve into new classes of race conditions that go beyond traditional limit-overrun exploits, uncovering vulnerabilities in website state machines. Learn techniques to manipulate states and transitions, enabling the forging of trusted data, misrouting of tokens, and masking of backdoors. Discover a refined methodology for efficient testing, recognizing high-risk patterns, and identifying subtle clues. Gain insights into overcoming network jitter and creating reproducible attacks using precision tooling adapted from HTTP Desync Attack research. Understand how to tailor attacks to different HTTP versions and target architectures, exploiting protocol-level design decisions and server implementation quirks. Access free online labs to immediately apply newly acquired skills in web security testing.
Syllabus
Smashing The State Machine: The True Potential Of Web Race Conditions by James Kettle | Nullcon Goa
Taught by
nullcon
Related Courses
Network SecurityGeorgia Institute of Technology via Udacity Proactive Computer Security
University of Colorado System via Coursera Identifying, Monitoring, and Analyzing Risk and Incident Response and Recovery
(ISC)² via Coursera Hacker101
HackerOne via Independent CNIT 127: Exploit Development
CNIT - City College of San Francisco via Independent