Главная
Study mode:
on
1
Intro
2
About me
3
Introduction and context
4
AMF for end-users
5
AMF for old-school hackers
6
AMF for web hackers
7
Adobe BlazeDS
8
Action Message Format (AMF)
9
State of art (research, tools)
10
Testing remote methods, today
11
Enterprise-grade applications
12
Security Testing Areas 36 Authentication
13
Say hello to Blazer
14
Blazer vo.2
15
Blazer - Architecture 2/2
16
DEMO 1
17
Blazer - Core techniques 1/3
18
Test case: SQL injection
19
Blazer - "Best-fit" heuristics 2/2
20
Coverage and Scalability
21
AMF Security Testing with Blazer 36 Authentication
22
Conclusions
23
Future improvements
Description:
Explore advanced techniques for testing Action Message Format (AMF) applications in this Black Hat USA 2012 conference talk. Delve into the challenges of bug hunting in AMF-based applications and discover a new automated gray-box testing approach. Learn about Blazer, a Burp Suite plugin that revolutionizes AMF fuzzing by dynamically generating objects from method signatures. Gain insights into improving coverage and effectiveness when targeting complex applications, and examine real-world vulnerabilities uncovered using this innovative tool. Follow along as the speaker demonstrates the methodology using Adobe BlazeDS as a server-side reference implementation. Acquire practical knowledge on making AMF testing more robust and efficient, covering topics such as authentication, SQL injection, and best-fit heuristics.

AMF Testing Made Easy

Black Hat
Add to list