albinowax - HTTP Desync Attacks: Smashing into the Cell Next Door - DEF CON 27 Conference

Поделиться
HTML-код
  • Опубликовано: 27 окт 2024

Комментарии • 28

  • @sakettestsakettest8009
    @sakettestsakettest8009 5 лет назад +55

    Massive respect to him...this guy is a genius.

  • @6544441
    @6544441 5 лет назад +15

    You can find the whitepaper, tool, and online labs at portswigger.net/research/http-desync-attacks-request-smuggling-reborn

    • @mo938
      @mo938 2 года назад

  • @0x1h0b
    @0x1h0b 4 года назад +9

    Man.. i love how good he explains.. huge respect sir..

  • @xXRedTheDragonXx
    @xXRedTheDragonXx 3 года назад +9

    This is legitimately one of the worst vulnerabilities ever discovered. Honestly, this should scare every developer, server host, backend developer, frontend developer, CDN developer, anyone who's software was exploited in the chain and every user on the internet. Being able to inject code to random users page with nothing but a few post requests is absolutely terrifying, and being able to steal plain-text creds is horrifying

  • @kof2002x
    @kof2002x 5 лет назад +14

    honestly i like the researches of albinowax "Respect"

  • @BeggarsAreChoosers
    @BeggarsAreChoosers 4 года назад +6

    As always, outstanding research material by James (albinowax). This is such a big material by itself, I don't know how to understand every bit of this attack. Just checked that his blog on this attack is around 26 pages long with lots of other pointers and links. It's almost kind of a book. I don't know I will be able to understand fully as only a Genius like him can make this type of material and only a Genious will understand it fully. This might take my entire life to go through all research materials that he alone contributes every year. His name will be in the history of Ethical Hacking.

  • @ChadChad1776
    @ChadChad1776 4 года назад +14

    Scariest talk I've ever watched.

  • @CropCircleSystems
    @CropCircleSystems 4 года назад +4

    Great exploits. I could smell this vulnerability almost as long as I can remember and it's just insane how long, far and wide it's still applicable after being documented over a decade ago. I never could have done and put together all this research and implemented such effective exploits. Thorough exploration of the problem space. Thorough documentation of cause and effect. GREAT presentation. My favorite from DEFCON 27. I was on the edge of my seat the entire time. On another note, I've been pronouncing the letter H wrong my entire life. Thank you so much for this albinowax!

  • @sveneFX
    @sveneFX 2 года назад

    Thx so much for sharing, this is insane - well done!

  • @UsamaAli-kr2cw
    @UsamaAli-kr2cw 2 года назад +1

    This is mind blowing research done by james :)

    • @jpphoton
      @jpphoton 2 месяца назад

      the vast domain space of http
      and a brilliant mind laying it down like Shakespeare
      extremely insightful
      thank you

  • @lPlanetarizado
    @lPlanetarizado 2 месяца назад

    this guy is amazing

  • @KeithMakank3
    @KeithMakank3 2 года назад

    Missed opertunity to call this a : Joiny Cache vulnerability

  • @nikivc
    @nikivc 4 года назад +1

    Super awesome, what a good talk !

  • @JuanBotes
    @JuanBotes 2 года назад

    Thanks for sharing your knowledge \o/

  • @KristyLeeDeTert-qr3yb
    @KristyLeeDeTert-qr3yb 3 месяца назад

    😊❤

  • @steiner254
    @steiner254 3 года назад

    This is awesome!

  • @alphawolf4446
    @alphawolf4446 4 года назад +1

    0 dislikes - that's my boy standard : )

  • @DaveKupratis
    @DaveKupratis 5 лет назад +1

    Very well done!

  • @FantubeChannel
    @FantubeChannel 5 лет назад +1

    Awesome!

  • @gddaredevil
    @gddaredevil Год назад

    *_great_*

  • @siddharthchhetry4218
    @siddharthchhetry4218 3 года назад

    Godly guy.

  • @iamkid4357
    @iamkid4357 4 года назад

    awesome

  • @amithc9429
    @amithc9429 4 года назад

    😍😍😍

  • @5uSWEq7t
    @5uSWEq7t 4 года назад +1

    wizard class hacker

  • @RyanLynch1
    @RyanLynch1 4 года назад +3

    wow I want to be that smart one day lol... then maybe I can get PayPal to give me 40k too haha

  • @TheIndiaView
    @TheIndiaView 3 года назад

    fucking awesome