Overview
Syllabus
Introduction
Who am I
Landside DSL
CWMP
Heros Explore
Heroesx Security
Must Implementation
Posture Protect
Outcome
Deutsche Telekom
Ireland
Who did it
Bonus Win
Ida Pro
Miss Fortune Cookie
Exploit
DSL Forum Certification
SSL TLS
XML
Threat Model
Hacking
Audit
Disclosure Timeline
FreeACS
Postit
Postit screenshots
We want preoff
Attack Surf
Test Fuzzing
XML NEX
BaseField
XSS
Payload Limitations
Remote Script
Admin User
Stack Overflow
Stack Overflow exploit
Game over
Script kiddie
OpenACS
JBoss
Misc Configuration Server
CSP
CSP in the wild
CSP in Java
CSP in PHP
Laravel Autoloading
Exploitable
Solutions
Defenses
Ongoing research
Thanks
Taught by
Security BSides London