Главная
Study mode:
on
1
Intro
2
Lobster Security Fallacy
3
Browser Exploitation
4
Limitations
5
Netflix
6
Singularity
7
RealWorld Examples
8
GeoCD Example
9
Bug Bounty Example
10
Service Workers
11
Attack Portfolio
12
Outro
Description:
Explore offensive JavaScript techniques for red teamers in this 33-minute conference talk from BSidesSF 2019. Delve into advanced methods for crafting JavaScript payloads that target internal network vulnerabilities with unprecedented speed. Learn about new reconnaissance techniques traditionally used post-malware implant that can now be applied pre-implant to gain network footholds from a browser. Examine real-world examples of external payloads targeting internal assets at major companies, and understand the process of responsible disclosure for intranet-facing bugs. Topics covered include the Lobster Security Fallacy, browser exploitation limitations, Netflix Singularity, Service Workers, and building an attack portfolio. Gain insights into cutting-edge AppSec strategies that go beyond pre-exploitation, challenging conventional norms in cybersecurity.

Offensive Javascript Techniques for Red Teamers

Security BSides San Francisco
Add to list