Главная
Study mode:
on
1
Introduction
2
Previous techniques
3
Simple spoofing attacks
4
Reflection attack
5
Reflection attacks
6
TCP Fast Open
7
TCP Security Limitations
8
ARP Version 6
9
TCP First Open Concept Attack
10
Link Local Addresses
11
IP Version 6
12
Protocols
13
Which server is most secure
14
SSL Validator
15
Main Schema
16
yandex bug bounty
17
results
18
questions
Description:
Explore advanced Server-Side Request Forgery (SSRF) techniques and real-world exploitation stories in this 48-minute conference talk from the Hack In The Box Security Conference. Delve into new attack vectors, including memcached and PHP FastCGI exploits, and learn how to leverage SSRF for direct socket communication with various applications. Discover expanded protocol usage beyond standard network libraries and gain insights from a comprehensive SSRF cheatsheet. Examine case studies of SSRF-related vulnerabilities in major platforms, with a focus on exploits targeting Yandex, a leading Russian Internet company. Gain valuable knowledge on web application security, network perimeter bypassing, and cutting-edge SSRF attack methodologies from security experts Vladimir Vorontsov and Alexander Golovko.

SSRF PWNs - New Techniques and Stories

Hack In The Box Security Conference
Add to list