Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

Circumventing Egress Filtering by Exploiting HTTP

Security BSides London via YouTube

Overview

Save Big on Coursera Plus. 7,000+ courses at $160 off. Limited Time Only!
Explore a Security BSides London conference talk on circumventing egress filtering through HTTP exploitation. Dive into the "transfer-encoding: chunked" mechanism for faster web shells, introduced during a red team engagement where traditional reverse and bind shells were ineffective. Learn about ChunkyTuna, a web shell that allows pivoting through compromised servers to reach deeper into target networks. Understand how this tool improves upon TUNNA by utilizing HTTP's chunked transfer encoding, offering near-direct access to STDIO streams of arbitrary processes or IO streams of TCP ports. Gain insights into advanced penetration testing techniques and network security vulnerabilities in this 23-minute presentation.

Syllabus

Circumventing egress filtering by exploiting HTTP - Lorenzo Grespan

Taught by

Security BSides London

Reviews

Start your review of Circumventing Egress Filtering by Exploiting HTTP

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.