Главная
Study mode:
on
1
Intro
2
NDC Security 2018
3
Insecure Deserialization
4
SSRF - Server Side Request Forgery
5
Edge Side Includes
6
Reverse proxy with caching
7
Dangers of ESI Injection
8
Finding and stopping ESI injection
9
JavaScript prototypes
10
Example: Logger definition
11
Exploring prototypes
12
Prototypes are mutable!
13
Common JavaScript patterns
14
Attack vectors
15
Avoiding prototype pollution attacks
16
Common API Problems
17
Classic HTTP Request smuggling
18
Detection and protection
Description:
Explore modern web vulnerabilities in this comprehensive conference talk from NDC Security. Delve into the evolution of lesser-known web application vulnerabilities that have gained prominence through bug bounty programs since 2018. Examine recurring issues and newly surfaced vulnerabilities, complete with live demonstrations. Gain insights into the causes of these bugs, learn detection techniques, and discover effective mitigation strategies. Cover topics such as insecure deserialization, server-side request forgery, edge side includes, JavaScript prototype pollution, API vulnerabilities, and HTTP request smuggling. Enhance your understanding of web security challenges and equip yourself with the knowledge to identify and eliminate these threats in your applications.

Modern Web Vulnerabilities 2020

NDC Conferences
Add to list
0:00 / 0:00