Главная
Study mode:
on
1
Introduction
2
What is Slide
3
Data Compression
4
What is Compression
5
Compression in HTTP
6
Compression HTTP
7
Data Compression Risks
8
XML Bomb
9
Protocol Specification
10
Impact on implementations
11
HTTP compression attack
12
Vulnerabilities
13
Attacking servers
14
Experiment setup
15
HTTP response compression
16
Pitfalls
17
Compression before authentication
18
Compression during input validation
19
Communication between units
20
Conclusion
Description:
Explore the security risks associated with data compression in HTTP protocols through this 39-minute conference talk from AppSecEU 2016 in Rome. Delve into the concept of compression bombs, their impact on implementations, and potential vulnerabilities in server systems. Learn about XML bombs, protocol specifications, and HTTP compression attacks. Examine experimental setups, HTTP response compression, and common pitfalls such as compression before authentication and during input validation. Gain insights into the challenges of communication between units and draw valuable conclusions for enhancing web application security.

Compression Bombs Strike Back

OWASP Foundation
Add to list