Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

Web Timing Attacks That Actually Work - Practical Techniques and Tools

DEFCONConference via YouTube

Overview

Save Big on Coursera Plus. 7,000+ courses at $160 off. Limited Time Only!
Explore practical web timing attacks in this 43-minute conference talk from DEF CON 32 that reveals how to exploit timing oracles hidden within websites. Discover novel attack concepts for extracting server secrets, including masked misconfigurations, blind data-structure injection, and hidden routes to restricted areas. Learn how recent advances have made these attacks both accurate and efficient, enabling reliable detection of sub-millisecond differentials in just ten seconds without special configurations. Gain hands-on experience with battle-tested open-source tools for both automated exploitation and custom attack scripting, and participate in a CTF challenge to practice these new skills. Master a refined methodology for transforming theoretical attack concepts into practical exploits, developed through extensive testing across thousands of websites. Understand how to harness this powerful and often overlooked side-channel for effective security testing.

Syllabus

DEF CON 32 - Listen to the Whispers: Web Timing Attacks that Actually Work - James Kettle

Taught by

DEFCONConference

Reviews

Start your review of Web Timing Attacks That Actually Work - Practical Techniques and Tools

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.