Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

HTTP Desync Attacks - Smashing into the Cell Next Door

Black Hat via YouTube

Overview

Explore advanced techniques for exploiting HTTP request isolation vulnerabilities in this Black Hat conference talk. Delve into HTTP desynchronization attacks that allow remote, unauthenticated attackers to manipulate web infrastructure, compromise visitor security, and exploit system weaknesses. Learn about the HTTP chain, desynchronization methods, detection strategies, and real-world case studies involving backend systems, cache poisoning, and CDNs. Examine specific examples, including attacks on PayPal's infrastructure, and witness a live demonstration. Gain insights into the underlying mechanisms of these attacks, their potential impact, and effective mitigation strategies to protect web applications from HTTP desync vulnerabilities.

Syllabus

Introduction
The HTTP Chain
Desynchronisation
Why does it work
Detection
Case Studies
Smuggling
Backend System
Cache Poisoning
CDNs
DOM
Local Feed
PayPal
PayPal Login
Demo
How to fix

Taught by

Black Hat

Reviews

Start your review of HTTP Desync Attacks - Smashing into the Cell Next Door

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.