Hacking Articles Tips Tricks Videos Tutorials
erhub 118. BugBounty 119. Huntr 120. Universocraft 121. Wireclub 122. AminoApps 123. Trakt 124. Giphy 125. Minecraft List 126. SEOClerks 127. Mix 128. Codecademy 129. Bandcamp 130. Poshmark 131. hackster 132. BodyBuilding 133. Mastodon 134. IFTTT 135. Anime…
l: Blackbird first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Browser-powered desync: New class of HTTP request smuggling attacks showcased at Black Hat USA
Browser-powered desync: New class of HTTP request smuggling attacks showcased at Black Hat USAPost Views: 252 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/08/Patreon-1.png Subscribe to Patreon to watch this episode.
Reading Time: 3 Minutes A new class of HTTP request smuggling attack allowed a security researcher to compromise multiple popular websites including Amazon and Akamai, break TLS, and exploit Apache servers.Speaking at Black Hat USA yesterday (August 10), James Kettle unveiled research that opens the new frontier in HTTP request smuggling – browser-powered desync attacks.
The briefing and it’s whitepaper, titled ‘Browser-Powered Desync Attacks: A New Frontier in HTTP Request Smuggling’, builds on Kettle’s previous research into desync attacks.
Traditional desync attacks poison the connection between a front-end and back-end server and are therefore impossible on websites that don’t use a front-end/back-end architecture.
However this new technique causes a desync between the front-end and the browser, allowing an attacker to “craft high-severity exploits without relying on malformed requests that browsers will never send”, Kettle noted.
This can expose a whole new range of websites to server-side request smuggling and enables an attacker to perform client-side variations of these attacks by inducing a victim’s browser to poison its own connection to a vulnerable web server.
Kettle demonstrated how he was able to turn a victim’s web browser into a desync delivery platform, shifting the request smuggling frontier by exposing single-server websites and internal networks.
He was able to combine cross-domain requests with server flaws to poison browser connection pools, install backdoors, and release desync worms – in turn compromising targets including Amazon, Apache, Akamai, Varnish, and multiple web VPNs.
See Also: So you want to be a hacker? Complete Offensive Security and Ethical Hacking Course DiscoveryKettle told attendees at the 25th anniversary of the annual hacking conference that four separate vulnerabilities led to the discovery of browser-powered desync attacks.
The first, involving request validation, leverages a technique in which an attacker can use two requests down the same connection with a valid host header in order to gain access to the host in the second request, because the reverse proxy only validates the first host.
The second, first-request routing, is a closely related flaw which occurs when the front-end uses the first request’s Host header to decide which back-end to route the request to, and then routes all subsequent requests from the same client connection down the same back-end connection.
Kettle also discovered a technique to detect connection-locked request smuggling by using a delay and reading the data early to decide if the front-end is using the Content-Length header.
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/08/819f-article-220810-james-k-1024x576.jpg
James Kettle presents at the annual hacking conference held in Las Vegas
If it is using the Content-Length it will time out, which will signify the difference between connection-locked HTTP/1 request smuggling and harmless HTTP pipelining.
A fourth vulnerability caused a desync known as CL.0/H2.0. Kettle was able to use this to compromise Amazon users’ accounts, enabling him to steal users’ requests and add them to his shopping list. He could capture all their requests, including tokens which could have enabled him to impersonate those users.
Speakin[...]
___________________________
@hacking_Attack
@Hacking_Video
Browser-powered desync: New class of HTTP request smuggling attacks showcased at Black Hat USA
Browser-powered desync: New class of HTTP request smuggling attacks showcased at Black Hat USAPost Views: 252 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/08/Patreon-1.png Subscribe to Patreon to watch this episode.
Reading Time: 3 Minutes A new class of HTTP request smuggling attack allowed a security researcher to compromise multiple popular websites including Amazon and Akamai, break TLS, and exploit Apache servers.Speaking at Black Hat USA yesterday (August 10), James Kettle unveiled research that opens the new frontier in HTTP request smuggling – browser-powered desync attacks.
The briefing and it’s whitepaper, titled ‘Browser-Powered Desync Attacks: A New Frontier in HTTP Request Smuggling’, builds on Kettle’s previous research into desync attacks.
Traditional desync attacks poison the connection between a front-end and back-end server and are therefore impossible on websites that don’t use a front-end/back-end architecture.
However this new technique causes a desync between the front-end and the browser, allowing an attacker to “craft high-severity exploits without relying on malformed requests that browsers will never send”, Kettle noted.
This can expose a whole new range of websites to server-side request smuggling and enables an attacker to perform client-side variations of these attacks by inducing a victim’s browser to poison its own connection to a vulnerable web server.
Kettle demonstrated how he was able to turn a victim’s web browser into a desync delivery platform, shifting the request smuggling frontier by exposing single-server websites and internal networks.
He was able to combine cross-domain requests with server flaws to poison browser connection pools, install backdoors, and release desync worms – in turn compromising targets including Amazon, Apache, Akamai, Varnish, and multiple web VPNs.
See Also: So you want to be a hacker? Complete Offensive Security and Ethical Hacking Course DiscoveryKettle told attendees at the 25th anniversary of the annual hacking conference that four separate vulnerabilities led to the discovery of browser-powered desync attacks.
The first, involving request validation, leverages a technique in which an attacker can use two requests down the same connection with a valid host header in order to gain access to the host in the second request, because the reverse proxy only validates the first host.
The second, first-request routing, is a closely related flaw which occurs when the front-end uses the first request’s Host header to decide which back-end to route the request to, and then routes all subsequent requests from the same client connection down the same back-end connection.
Kettle also discovered a technique to detect connection-locked request smuggling by using a delay and reading the data early to decide if the front-end is using the Content-Length header.
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/08/819f-article-220810-james-k-1024x576.jpg
James Kettle presents at the annual hacking conference held in Las Vegas
If it is using the Content-Length it will time out, which will signify the difference between connection-locked HTTP/1 request smuggling and harmless HTTP pipelining.
A fourth vulnerability caused a desync known as CL.0/H2.0. Kettle was able to use this to compromise Amazon users’ accounts, enabling him to steal users’ requests and add them to his shopping list. He could capture all their requests, including tokens which could have enabled him to impersonate those users.
Speakin[...]
___________________________
@hacking_Attack
@Hacking_Video
Black Hat Ethical Hacking
Browser-powered desync: New class of HTTP request smuggling attacks showcased at Black Hat USA | Black Hat Ethical Hacking
A new class of HTTP request smuggling attack allowed a security researcher to compromise multiple popular websites including Amazon and Akamai, break TLS, and exploit Apache servers.
Black Hat Ethical Hacking
Browser-powered desync: New class of HTTP request smuggling attacks showcased at Black Hat USA
___________________________
@hacking_Attack
@Hacking_Video
Browser-powered desync: New class of HTTP request smuggling attacks showcased at Black Hat USA
___________________________
@hacking_Attack
@Hacking_Video
Black Hat Ethical Hacking
Browser-powered desync: New class of HTTP request smuggling attacks showcased at Black Hat USA | Black Hat Ethical Hacking
A new class of HTTP request smuggling attack allowed a security researcher to compromise multiple popular websites including Amazon and Akamai, break TLS, and exploit Apache servers.
prevent xss
https://www.reddit.com/r/Pentesting/comments/wn0pak/prevent_xss/
hello Is setting the cookie to http only is enough to protect against xss attacks? submitted by /u/Objective_Fruit_5995 (https://www.reddit.com/user/Objective_Fruit_5995)
[link] (https://www.reddit.com/r/Pentesting/comments/wn0pak/prevent_xss/) [comments] (https://www.reddit.com/r/Pentesting/comments/wn0pak/prevent_xss/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/wn0pak/prevent_xss/
hello Is setting the cookie to http only is enough to protect against xss attacks? submitted by /u/Objective_Fruit_5995 (https://www.reddit.com/user/Objective_Fruit_5995)
[link] (https://www.reddit.com/r/Pentesting/comments/wn0pak/prevent_xss/) [comments] (https://www.reddit.com/r/Pentesting/comments/wn0pak/prevent_xss/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
prevent xss
hello Is setting the cookie to http only is enough to protect against xss attacks?
Dark Reading: Attacks/Breaches
Patch Madness: Vendor Bug Advisories Are Broken, So Broken
Duston Childs and Brian Gorenc of ZDI take the opportunity at Black Hat USA to break down the many vulnerability disclosure issues making patch prioritization a nightmare scenario for many orgs.
___________________________
@hacking_Attack
@Hacking_Video
Patch Madness: Vendor Bug Advisories Are Broken, So Broken
Duston Childs and Brian Gorenc of ZDI take the opportunity at Black Hat USA to break down the many vulnerability disclosure issues making patch prioritization a nightmare scenario for many orgs.
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
Patch Madness: Vendor Bug Advisories Are Broken, So Broken
Dustin Childs and Brian Gorenc of ZDI take the opportunity at Black Hat USA to break down the many vulnerability disclosure issues making patch prioritization a nightmare scenario for many orgs.
Directory Traversal — Explicação [PT/BR]
https://medium.com/@anonymindsec/directory-traversal-explica%C3%A7%C3%A3o-pt-br-a644c94380ce?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@anonymindsec/directory-traversal-explica%C3%A7%C3%A3o-pt-br-a644c94380ce?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Directory Traversal — Explicação [PT/BR]
Hoje eu resolvi fazer um pouco diferente, normalmente eu tenho mais o hábito de escrever sobre write-ups do que sobre as vulnerabilidades…
Hoje eu resolvi fazer um pouco diferente, normalmente eu tenho mais o hábito de escrever sobre write-ups do que sobre as vulnerabilidades…Continue reading on Medium » (https://medium.com/@anonymindsec/directory-traversal-explica%C3%A7%C3%A3o-pt-br-a644c94380ce?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Directory Traversal — Explicação [PT/BR]
Hoje eu resolvi fazer um pouco diferente, normalmente eu tenho mais o hábito de escrever sobre write-ups do que sobre as vulnerabilidades…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Building Tools for Good
Moral Ambiguity and Software Security
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Building Tools for Good
Moral Ambiguity and Software Security
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Building Tools for Good
Moral Ambiguity and Software Security
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Server Side Template Injections By Hashar Mujahid.
https://cdn-images-1.medium.com/max/1065/1*Cqj9YCQBnfhGLgdqLvIlvw.png
In this blog, we are going to learn bout what server-side template injections are and how they work by solving Portswiggers labs.
Continue reading on InfoSec Write-ups »
___________________________
@hacking_Attack
@Hacking_Video
Server Side Template Injections By Hashar Mujahid.
https://cdn-images-1.medium.com/max/1065/1*Cqj9YCQBnfhGLgdqLvIlvw.png
In this blog, we are going to learn bout what server-side template injections are and how they work by solving Portswiggers labs.
Continue reading on InfoSec Write-ups »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Server Side Template Injections By Hashar Mujahid.
In this blog, we are going to learn bout what server-side template injections are and how they work by solving Portswiggers labs.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Las 9 mejores prácticas de seguridad de Node.js
https://cdn-images-1.medium.com/max/1023/0*_AVMgOJQH0l5-Ytr
PUBLICADO EN 12 AGOSTO, 2022 EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Las 9 mejores prácticas de seguridad de Node.js
https://cdn-images-1.medium.com/max/1023/0*_AVMgOJQH0l5-Ytr
PUBLICADO EN 12 AGOSTO, 2022 EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Las 9 mejores prácticas de seguridad de Node.js para que los desarrolladores eviten el hackeo de aplicaciones Node.js
PUBLICADO EN 12 AGOSTO, 2022 EHACKING
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Уменьшение приватного ключа через скалярное умножение используем библиотеку ECPy + Google Colab
https://cdn-images-1.medium.com/max/600/0*QEoHo1jyS3pQg1ti.png
В этой статье мы постараемся показать как можно уменьшить приватный ключ зная только утечку из списка «BLOCKCHAIN FOLBIT LEAKS» и…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Уменьшение приватного ключа через скалярное умножение используем библиотеку ECPy + Google Colab
https://cdn-images-1.medium.com/max/600/0*QEoHo1jyS3pQg1ti.png
В этой статье мы постараемся показать как можно уменьшить приватный ключ зная только утечку из списка «BLOCKCHAIN FOLBIT LEAKS» и…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Уменьшение приватного ключа через скалярное умножение используем библиотеку ECPy + Google Colab
В этой статье мы постараемся показать как можно уменьшить приватный ключ зная только утечку из списка «BLOCKCHAIN FOLBIT LEAKS» и публичный…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Upgrade & Update Kali Linux
https://cdn-images-1.medium.com/max/800/0*fyIw8Sg9AA96tay0
Welcome future Crack’s of Cybersecurity to my first post this time we are going to learn how to update Kali Linux.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Upgrade & Update Kali Linux
https://cdn-images-1.medium.com/max/800/0*fyIw8Sg9AA96tay0
Welcome future Crack’s of Cybersecurity to my first post this time we are going to learn how to update Kali Linux.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Upgrade & Update Kali Linux
Welcome future Crack’s of Cybersecurity to my first post this time we are going to learn how to update Kali Linux.