AMF Security Testing with Blazer 36 Authentication
22
Conclusions
23
Future improvements
Description:
Explore advanced techniques for testing Action Message Format (AMF) applications in this Black Hat USA 2012 conference talk. Delve into the challenges of bug hunting in AMF-based applications and discover a new automated gray-box testing approach. Learn about Blazer, a Burp Suite plugin that revolutionizes AMF fuzzing by dynamically generating objects from method signatures. Gain insights into improving coverage and effectiveness when targeting complex applications, and examine real-world vulnerabilities uncovered using this innovative tool. Follow along as the speaker demonstrates the methodology using Adobe BlazeDS as a server-side reference implementation. Acquire practical knowledge on making AMF testing more robust and efficient, covering topics such as authentication, SQL injection, and best-fit heuristics.