Главная
Study mode:
on
1
Introduction
2
What is Compression
3
What Compression means
4
Compression Oracle Attack
5
Observing Encrypted Traffic
6
Crime Massive Code
7
Future Attacks
8
Time
9
Breach
10
TLS VPNs
11
The Attack
12
Requirements
13
Setup
14
Chrome
15
Detection
16
Compression Oracle
17
CloudFlare
18
My Take
19
Summary
20
Questions
Description:
Explore compression oracle attacks on VPN networks in this 43-minute Black Hat conference talk. Delve into the vulnerabilities of browser requests and responses tunneling HTTP traffic through VPNs, and investigate potential attacks on ESP Compression and other encryption-based optimizations in tunneled traffic. Learn about compression basics, observe encrypted traffic, and understand the CRIME attack. Examine the setup, requirements, and detection methods for these attacks, with a focus on Chrome and CloudFlare implementations. Gain insights into future attack possibilities, including TimeBreach and TLS VPNs. Conclude with a summary and Q&A session led by speaker Ahamed Nafeez.

Compression Oracle Attacks on VPN Networks

Black Hat
Add to list