Главная
Study mode:
on
1
Intro
2
Canvas
3
Canvas Demo
4
Quake Demo
5
Video Audio
6
Geolocation
7
Drag and Drop
8
Web Notifications
9
The Hacker
10
Recon
11
Crosssite scripting
12
Examples
13
Attack and Defense Labs
14
XML HTTP Requests
15
Scanning the Network
16
The Next Day
17
GeoLocate
18
Autocomplete
19
Social Engineering
20
Directory
21
File Server
22
Pippy
23
DOS
24
Spam
25
Beef
26
Network
27
Pretty Test
28
Summary
Description:
Explore the security implications of HTML5 in this 41-minute conference talk from BruCON Security Conference. Delve into HTML5's new features from an attacker's perspective, examining potential vulnerabilities and attack vectors. Learn about semantic web, editable content, form validation, local storage, and video support, while understanding how these advancements can be exploited. Discover how attackers can leverage HTML5 to cause havoc on machines and even build browser-based botnets. Through demonstrations and examples, gain insights into canvas manipulation, geolocation risks, drag-and-drop vulnerabilities, and web notification exploits. Examine cross-site scripting techniques, XML HTTP request vulnerabilities, and network scanning possibilities. Explore defense strategies and participate in attack and defense labs to better understand and mitigate these new security challenges.

HTML5 - A Whole New Attack Vector

BruCON Security Conference
Add to list
0:00 / 0:00