DNS hijacking using cloud providers - Frans Rosén - Security Fest 2017

preview_player
Показать описание
A few years ago, Frans and his team posted an article on Detectify Labs regarding domain hijacking using services like AWS, Heroku and GitHub. These issues still remains and are still affecting a lot of companies. Jonathan Claudius from Mozilla even calls “Subdomain takeover” “the new XSS”. Since then, many tools have popped up to spot these sorts of vulnerabilities. Frans will go through both the currently disclosed and the non-disclosed ways to take control over domains and will share the specific techniques involved.
Рекомендации по теме
Комментарии
Автор

yes me too why they hide : ( ? I'm worry about that : (

mrdott
Автор

I wanna
dat
"secret super secret awesome hacker stuff"
@35:20

rootlabs