Practical Attacks Using HTTP Request Smuggling by @defparam

แชร์
ฝัง
  • เผยแพร่เมื่อ 28 พ.ย. 2024

ความคิดเห็น • 38

  • @eyezikandexploits
    @eyezikandexploits 4 วันที่ผ่านมา

    Trying to get an absolute in depth understanding of each major vulnerability type, this has helped with my smuggling step

  • @domaincontroller
    @domaincontroller 4 ปีที่แล้ว +2

    01:10 interest low stack system/integration/protocol bugs 01:27 agenda 02:04 quick introduction, CL.TE /TE.CL "HTTP Desync Attacks: Smashing into the Cell Next Door " James Kettle, th-cam.com/video/w-eJM2Pc0KI/w-d-xo.html watchfire paper, 2005 shorturl.at/cfstN
    ======================================
    CL.TE Desync Attack
    ======================================
    03:21 CL.TE which is the front-end.back-end 03:35 the front-end will interpret a web request using its content-type header and the back-end will interpret the same request using the transfer-encoded header 03:51 here we have an attacker, post request, T.E header is malformed 04:18 Back-end ignores the content-length
    =============================
    TE.CL Desync Attack
    =============================
    05:58 [...]
    08:14 testing for request smuggling 08:37 github.com/defparam/smuggler
    09:58 Impact radius of request smuggling 10:14 Open Desync, the3 most dangerous of the three 10:28 IP Desync 10:51 Self Desync, VPN, VPS
    =============================
    Practical Attack
    =============================
    11:20 Recon stories

  • @tanercoder1915
    @tanercoder1915 4 ปีที่แล้ว +2

    mind blown! felt sorry for sysadmins for the consequences of his very last attack in this presentation. highly impactful attack indeed.

  • @pentestical
    @pentestical 4 ปีที่แล้ว +5

    Exactly what I need. Impressive stuff!

  • @ShailuSharma-y3k
    @ShailuSharma-y3k 4 หลายเดือนก่อน

    The stuff is really great. Thanks a lot !!

  • @m.waheedanwar7105
    @m.waheedanwar7105 4 ปีที่แล้ว

    Thank you for sharing.One of great teaching class i ever had.

  • @1772prem
    @1772prem 4 ปีที่แล้ว

    Cool PoC, Great session on HTTP smuggling attack.

  • @hydroflows
    @hydroflows 4 ปีที่แล้ว

    seeing the view count gives me the warm n fuzzies cus i know im super early to the party
    you ladies and gents are super rad and i couldnt be more excited to start hunting

  • @khammama2974
    @khammama2974 4 ปีที่แล้ว +1

    18:48 recon story#2 is about api.zomato.com🕵️ got a bounty of. 15k USD

  • @testing7468
    @testing7468 2 ปีที่แล้ว

    The last one was mind blowing

  • @thedarkarmy8713
    @thedarkarmy8713 10 หลายเดือนก่อน

    Does HTTP Request smuggling, just works on POST method, or also on GET ? I have heard it just works on POST method..

  • @ibrahime316
    @ibrahime316 3 ปีที่แล้ว +1

    Is their github page for the test server , I wanna test my self

  • @jondo-vh8tx
    @jondo-vh8tx 7 หลายเดือนก่อน

    14:40 the takeway i love it. i was in talk with a pretty big sec tech company . one of their guys tried to act like a wise guy: there is no risk with a robots.txt. ok sure kiddo.

  • @rahulmyakala9816
    @rahulmyakala9816 4 ปีที่แล้ว

    Hello sir. I have a question I couldn't find how to do that. There are 15 numbers from 1-15. It can generate any number randomly. How can we identify which number is being generated?

  • @thebest152
    @thebest152 3 ปีที่แล้ว +2

    Hi Nahamsec,
    Can you share the lab so I can practice?

  • @lancemarchetti8673
    @lancemarchetti8673 2 ปีที่แล้ว

    This was trooly amayzing

  • @hdphoenix29
    @hdphoenix29 4 ปีที่แล้ว

    Amazing stuff ! thanks a lot

  • @m0niruzzaman
    @m0niruzzaman 4 ปีที่แล้ว

    Thanks

  • @Andrei-ds8qv
    @Andrei-ds8qv ปีที่แล้ว

    Thank you

  • @nowonder9466
    @nowonder9466 4 ปีที่แล้ว

    I needed this.

  • @dwilliams877
    @dwilliams877 4 ปีที่แล้ว

    This was fascinating!

  • @yashjain1449
    @yashjain1449 4 ปีที่แล้ว

    Amazing stuff

  • @Imhamzaazam
    @Imhamzaazam 4 ปีที่แล้ว

    Thankyou!

  • @goodboy8833
    @goodboy8833 4 ปีที่แล้ว +2

    Why don't you ppl invite ippsec

  • @hidayatbachtar
    @hidayatbachtar 3 ปีที่แล้ว

    how attacker poisoing the HTTP, but Victim access on HTTPS ?
    can it's still work ? or not? if work, how?

    • @omarataallah9451
      @omarataallah9451 2 ปีที่แล้ว

      in this vulnerability, there is no key different between http and https, but the thing you must looking for is the http version, if it's http/2.0 then you have to try another ways to exploit it by downgrading the http version to 1

    • @hidayatbachtar
      @hidayatbachtar 2 ปีที่แล้ว

      @@omarataallah9451 ouh thats about http version not http / https ? am i right?

    • @omarataallah9451
      @omarataallah9451 2 ปีที่แล้ว

      @@hidayatbachtar true

  • @tommysuriel
    @tommysuriel 4 ปีที่แล้ว

    This is GOLD!

  • @iamkid4357
    @iamkid4357 4 ปีที่แล้ว

    wow amazing

  • @hamrodesh4362
    @hamrodesh4362 4 ปีที่แล้ว +1

    Tcm hair 😂