DEF CON 32 - Relative Path File Injection The Next Evolution in RPO - Ian Hickey
Description:
Explore a groundbreaking security presentation that unveils Relative Path File Injection (RPFI), a novel attack vector evolving from traditional Relative Path Overwrite techniques. Learn how attackers can manipulate trusted websites into unwitting malware delivery platforms by exploiting browser path handling quirks. Dive deep into the technical mechanics of RPFI attacks through live demonstrations and practical examples, while gaining access to an open-source repository containing proof-of-concept implementations. Understand how this polyglot-based attack methodology takes advantage of discrepancies between web specifications and real-world browser implementations, representing a significant advancement in web security threats. Master the skills needed to identify and detect these sophisticated vulnerabilities in production environments, equipping yourself with essential knowledge for modern web security defense.
Relative Path File Injection: The Next Evolution in RPO