Главная
Study mode:
on
1
Introduction
2
Attacking Modern Web Technologies
3
About Frans Rosen
4
Outline of the talk
5
AppCache
6
Dropbox
7
Upload Policies
8
Custom Policies
9
Postmessage
10
Document Service
11
Clientside Race Conditions
12
Example
13
Speed Bumps
14
jQuery
15
What could I add to it
16
One more thing
17
Questions
Description:
Dive into a comprehensive exploration of modern web technology vulnerabilities with top-ranked white-hat hacker Frans Rosén in this 43-minute conference talk from OWASP AppSec EU 2018. Discover methodologies for accessing private Slack tokens through postMessage and WebSocket-reconnect techniques, and learn how misconfigured AWS and Google Cloud settings can lead to full asset control by attackers. Gain insights into new hacks, bug bounty experiences, and eye-opening revelations about the true security of seemingly safe protocols and policies. Topics covered include AppCache, Dropbox upload policies, postmessage vulnerabilities, document service exploits, clientside race conditions, jQuery security issues, and more. Conclude with a Q&A session to deepen your understanding of cutting-edge web security challenges.

Attacking Modern Web Technologies

OWASP Foundation
Add to list