Главная
Study mode:
on
1
Intro
2
Penetration Tester vs Vulnerability Assessment
3
HTTP Pillage
4
Username Enumeration
5
Live Demo
6
Edit Job
7
Response Flag
8
Dictionary
9
Squiggly Bracket
10
Status codes
11
Spinning up another node
12
Thread count
13
Result
14
Local hosting
15
Search tip
16
verbose error message
17
Increasing exploitability
18
Expired tokens
19
Django envy
20
Forgot password mechanism
21
Character sets
22
Password reset
23
Weak tokens
24
Denial of service
25
Outro
Description:
Explore the world of distributed HTTP-based attacks in this 40-minute LASCON conference talk. Learn about Httpillage, a tool designed to distribute attacks across multiple nodes, simulating real-world threats more effectively than single-host attacks. Discover how to conduct online password brute-force attempts, denial of service attacks, and application enumeration with increased speed and effectiveness. Follow along with live demonstrations of common attacks across multiple nodes, including brute-forcing time-based password reset tokens. Gain insights into providing proper impact demonstrations during penetration testing, and understand the limitations of traditional single-host approaches. Delve into topics such as username enumeration, job response flags, dictionary attacks, status codes, and weak token exploitation. Enhance your understanding of application security testing and learn how to better model real-world threats in your assessments.

Httpillage - Calling All Nodes

LASCON
Add to list