Главная
Study mode:
on
1
Introduction
2
Agenda
3
JSON Attacks
4
Data Libraries
5
Requirements
6
Classification
7
List of libraries
8
Jason
9
JavaScriptserializer
10
JSONserializer
11
Example
12
Shoutout
13
Dotnet
14
Demo
15
Not a problem in Jason
16
Serializers
17
JSON parsers
18
Demonstration
19
XML payload
20
Victim server
21
Summary
22
Questions
Description:
Explore the critical security implications of JSON attacks in this 43-minute Black Hat conference talk. Delve into the aftermath of the 2016 Java deserialization apocalypse and its impact on vulnerability awareness. Learn about various JSON attacks, data libraries, and their classifications. Examine specific libraries like Jason, JavaScriptserializer, and JSONserializer through practical examples and demonstrations. Understand the differences between JSON serializers and parsers, and witness a live demonstration of an XML payload attack on a victim server. Gain valuable insights into this often overlooked security concern and be prepared to address questions on the topic.

Friday the 13th - JSON Attacks

Black Hat
Add to list
0:00 / 0:00