Главная
Study mode:
on
1
Intro
2
White Hat Security
3
Matts Background
4
How the Web Works
5
Browser Bots
6
More Aggressive
7
Login Detection
8
Like Button
9
Internet Hacking
10
Cross Site Scripting
11
iframes
12
Raavan
13
Application Level Distributed Denial of Service
14
Browser Scope
15
Firefox
16
Conclusion
17
Traditional Methods
18
Advertising Ecosystem
19
Advertising Network
20
Kobi
21
Browser Renting
22
The Economics
23
The Ad Network
24
Demo
25
PhantomJS
26
Browserminute
27
Ad Network
28
Connection Flood
29
Ass Badge
30
Traffic
31
Half a gig
32
Almost a gig
33
Total hits
34
I was still counting up
35
I had bought 10000
36
We had tacit permission to Akamai
37
Deploying the FTP Bypass
38
Turning it off
39
Why attack this way
40
OpenX vulnerability
41
Web security challenges
Description:
Explore the potential of browser-based botnets in this 48-minute OWASP Foundation conference talk by Jeremiah Grossman and Matt Johanssen. Discover how online advertising networks can be exploited to distribute malicious JavaScript, creating large-scale browser botnets for pennies. Learn about the real-world implications of this technique, including DDoS attacks, spam campaigns, and password cracking. Examine the power of HTML5 and JavaScript in commandeering browsers without leaving traces. Understand why traditional methods of creating botnets fall short compared to leveraging advertising networks. Gain insights into the economics of browser renting and witness live demonstrations of attacks against well-protected targets. Delve into topics such as Cross-Site Request Forgery, application-level DDoS, and the challenges of web security in this eye-opening presentation.

Million Browser Botnet - Creating a JavaScript-Driven Browser Botnet for DDoS Attacks

OWASP Foundation
Add to list
0:00 / 0:00