DEF CON 23 - Jason Haddix - How to Shot Web: Web and mobile hacking in 2015

preview_player
Показать описание
2014 was a year of unprecedented participation in crowdsourced and static bug bounty programs, and 2015 looks like a trendmaker. Join Jason as he explores successful tactics and tools used by himself and the best bug hunters. Practical methodologies, tools, and tips make you better at hacking websites and mobile apps to claim those bounties. Convert edge-case vulnerabilities to practical pwnage even on presumably heavily tested sites. These are tips and tricks that the every-tester can take home and use. Jason will focus on philosophy, discovery, mapping, tactical fuzzing (XSS, SQLi, LFI, ++), CSRF, web services, and mobile vulnerabilities. In many cases we will explore these attacks down to the parameter, teaching the tester common places to look when searching for certain bugs. In addition he will cover common evasions to filters and as many time saving techniques he can fit in.

Speaker Bio:
Jason is the Director of Technical Operations at Bugcrowd. Jason trains and works with internal application security engineers to triage and validate hardcore vulnerabilities in mobile, web, and IoT applications/devices. He also works with Bugcrowd to improve the security industries relations with the researchers. Jason’s interests and areas of expertise include, mobile penetration testing, black box web application auditing, network/infrastructural security assessments, binary reverse engineering, and static analysis.
Рекомендации по теме
Комментарии
Автор

jason just remembered me to daru-kun such as 'superhaka' on Steins;Gate anime, then he had meet his daughter from future, it's cool

neetizen
Автор

Titter would actually live up to its name

DotNetRussell
Автор

39:20 a CSRF python tool by arvind doriswamy
Seems like a South Indian name👍

umessr
Автор

Bir insan evladı da kapanışta teşekkür edilen "Fatih" kimdir dememiş.

Автор

You're the smart version of Peter griffin from family guy .

ShamseddineHireche
Автор

So bugcrowdlabs/maps isnt available anymore? sounds like a great tool, is their something similar or can we get access somewhere else?

jenniferwood
Автор

Where can i find the polyglot paylaods?

HassanRaza-ekmv
Автор

I think the facebook page for bugs disclosed is not working now. Did anyone get any updated link for that?

hackersguild
Автор

where are the links for the show notes this Video? Can I get it ?

dsdgaming
Автор

I can't...
Watch this...
I can >:)

hashintelligence
Автор

Can someone explain to me why identifying platform is important?

bancer