Learn how to enhance web server security by comparing responses from multiple servers in this conference talk from CarolinaCon. Explore an innovative approach to detecting zero-day exploits by leveraging the observation that high-impact exploits rarely affect different web servers on separate operating systems simultaneously. Discover the methodology of polling responses from multiple server configurations, such as Apache on Linux and IIS on Windows, to identify potential security threats before delivering the final response. Gain insights into exploit detection techniques that go beyond traditional signatures and AI-based solutions, offering a practical strategy for improving web server security through comparative analysis.
Overview
Syllabus
"Ok I guess we doin' shells now:" Creating a Secure Web Server from Two Vulnerable Web Servers
Taught by
CarolinaCon