Главная
Study mode:
on
1
Introduction
2
Who am I
3
Credits
4
Agenda
5
Why HTTP2
6
HTTP1 Problems
7
Who Uses HTTP2
8
Components of HTTP
9
Frame
10
New Attacks
11
Research
12
Implementation
13
Flow Control Mechanism
14
Low Data Rate Attack
15
Video Demo
16
Industry Multiplexing
17
Attack Flow
18
Attack Flow Demo
19
Header Compression
20
HPack
21
Dynamic Table
22
Funny Story
23
What can we do
24
Option 1 Abandon HTTP2
25
Option 2 Patch
26
Option 3 Patch
27
Virtual Patching
28
Key takeaways
29
Technical details
Description:
Explore the emerging HTTP/2 protocol and its vulnerabilities in this Black Hat conference talk. Delve into the rapid adoption of HTTP/2 by major internet players and its role as a transition layer for web traffic. Discover new attack vectors targeting HTTP/2's components, including the flow control mechanism and header compression. Learn about the low data rate attack and industry multiplexing attack through video demonstrations. Examine potential solutions, from abandoning HTTP/2 to implementing patches and virtual patching. Gain key insights and technical details to better understand the security implications of this next-generation internet foundation.

Hacking HTTP/2 - New Attacks on the Internet's Next Generation Foundation

Black Hat
Add to list
0:00 / 0:00