What’s Wrong with WebSocket APIs - Unveiling Vulnerabilities in WebSocket APIs - Mikhail Egorov from csrf Watch Video

Preview(s):

Play Video:
(Note: The default playback of the video is HD VERSION. If your browser is buffering the video slowly, please play the REGULAR MP4 VERSION or Open The Video below for better experience. Thank you!)
⏲ Duration: 22 min 85 sec
✓ Published: 27-Feb-2020
Open HD Video
Open MP4 Video
Download HD Video
Download MP4 Video
Description:
WebSocket protocol is many times more efficient than HTTP. In recent years we can observe that developers tend to implement functionality in the form of WebSocket APIs instead of traditional REST APIs, that use HTTP. Modern technologies and frameworks simplify the building of efficient WebSocket APIs. We can name GraphQL subscriptions or Websocket APIs supported in Amazon API Gateway.nnWebSockets APIs have a different security model compared to REST APIs, resulting in unique attack vectors. Neve

Share with your friends:

Whatsapp | Viber | Telegram | Line | SMS
Email | Twitter | Reddit | Tumblr | Pinterest

Related Videos

WebSocket protocol is many times more efficient than HTTP. In recent years we can observe that developers tend to implement functionality in the form of WebSocket APIs instead of traditional REST APIs, that use HTTP. Modern technologies and frameworks simplify the building of efficient WebSocket APIs. We can name GraphQL subscriptions or Websocket APIs supported in Amazon API Gateway.nnWebSockets APIs have a different security model compared to REST APIs, resulting in unique attack vectors. Neve
⏲ 22 min 85 sec ✓ 27-Feb-2020
Web application insecurities often undermine IT infrastructure and with the ever-increasing complexity and reliance on web applications, understanding these vulnerabilities is an important step to securing the IT environment.nnWe'll continue to explore more common vulnerabilities found in today's web applications, take a look at exploitation examples, case-studies and how to resolve these issues. In this talk we'll touch on some of the following topics:nn* Session Hijackingn* Cross-Site
⏲ 30 min 39 sec ✓ 30-Oct-2010
It's only security penetration test for cyber-warrior team. There is no vulnerability.nn I'm a Cyber-Warrior member and i testing captcha security.
⏲ 1 min 17 sec ✓ 09-Dec-2012
Since cookies store sensitive data (session ID, CSRF token, etc.) they are interesting from an attacker's point of view. As it turns out, quite many web applications (including sensitive ones like bitcoin platforms) have cookie related vulnerabilities, that lead, for example, to user impersonation, remote cookie tampering, XSS and more.nnAt DeepSec 2015 Dawid Czagan (Silesia Security Lab) explained what to do when tackling cookies in modern browsers.
⏲ 25 min 33 sec ✓ 02-Feb-2016
Computerphile
⏲ 8 minutes 34 seconds 👁 757.4K
This is a demo of a PoC I wrote exploiting a bug in Coinbase.com's OAuth implementation. It was possible to retrieve the OAuth app authorization form as one user and forward it (along with the CSRF token's etc) to the victim, with Javascript to autosubmit the form. Coinbase was not confirming the form was generated by the victim and so it was possible for an attacker to authorize their malicious app on the users account without their confirmation. All the victim was required to do was view a web
⏲ 94 sec ✓ 06-May-2013
Har du noen gang vært redd for å gjøre massive omskrivninger av koden din for å øke lesbarhet? Har du noen gang vært nervøs ved bytte av server, versjoner etc? Automatisert regresjonstest er din reddende engel!nnHva gjør man når:nn...det er særdeles høye krav til kvalitet og regresjonsfeil er utelukket?nn...man må endre en applikasjon med nærmest ingen testdekning?nn...når tester kun dekker den delen av programmet som er endret, men ikke annen funksjonalitet?nnVi har utviklet en fr
⏲ 33 min 5 sec ✓ 10-Sep-2014
The focus of many application security programs has long been the OWASP Top 10 or SANS Top 25 vulnerabilities. While there are many SAST solutions that can identify these technical vulnerabilities such as SQLi, CSRF or XEE, SAST is not effective in identifying vulnerabilities that require context such as conditions leading to business logic, data leakage or hard-coded secrets.nWhile pattern-matching techniques can be used to identify the symptoms of an injection vulnerability across any code-bas
⏲ 32 min 81 sec ✓ 29-Apr-2020
Web Apps Security Series Part 4 - CSRF
⏲ 6 min 83 sec ✓ 03-Mar-2013

Related Video Searches

Back to Search

«Back to csrf Videos

Search csrf Desi Porn
Search csrf MMS Porn
Search csrf XXX Videos
Search csrf HD Videos
Search csrf XXX Posts
Search csrf Photos
Search csrf Leaks
Search csrf Web Series
Search csrf Pics
Search csrf VIP XXX

Search Videos

Recent Searches

aunty ki chudai xxxnia | bangladeshi sexy actress nasrin nude song | 抖音负面舆情怎么删除?抖音负面舆情删除找(电报:uuxy007) ums | 卢旺达购物数据卖数据shuju88 c0m卢旺达购物数据 数据检测124空号检测124筛料平台ampzebnh | 石家庄代孕妈妈一般多少钱微信10951068石家庄代孕妈妈一般多少钱石家庄代孕妈妈一般多少钱 0102v | ilov3inga | bangal cex video | randi an old man sex para acts project mali fake | 推特怎么屏蔽营销号信息【排名代做游览⭐seo8 vip】youtube营销是什么【排名代做游览⭐seo8 vip】google试管推广⏩排名代做游览⭐seo8 vip⏪4qq0 | natalie roush nude cheerleader teasing video leaks | eva elfie nude sextape porn video leaked mp4 | سعوديه مربربه تانجو | xxx sex gal full tv bangla setwo aunty bath sex hot xxx videosnny lion videofemale news anchor sexy news videoideoian female news anchor sexy news videodai 3gp videos page xvideos com xvideos indian videos page free nadiyarachna sex man fucking female xxx urmila mxxx anjali mahta babita je adalt saxy hd ph3gp sex je nayanthara nude sexan mimad | indian parking girl boobs pressed sex | 上海泥城怎么找小姐全套服务123美女多网止▷w2637 com125哪个会所找附近小姐店▷哪个酒店同城約妹子▷本地保健服务叫小姐怎么找amp986129 | fliz m | natsu bad bitch | 【实时聊天记录】查询微信99740112微信删除了的聊天记录怎么看 tdm | triple in 40 russian romance movie 2020 | nilimtomba | eoejiti1i o | adda with bong beauty saree blogger | xxxxiran | ඉන්දියාව | asmr dijilatin adek | 极速赛车【ylcp888 cc】云顶国际yd8888784 | simran singh nude stripchat live 4 | 杭州南站新茶嫩茶海选(v电✅16511000789老李✅)【快速安排】最靠谱的外围模特经纪m8ue | koplo full sexshi clips | film jadul gadis di perkosa | xoejte fbry | کراچی سمندر سکس | shemale gay fuck young boy hard | xnxxxxxxxxxxxxxxxxxxxxxx | twice what is love stag | vanimo sandaun png koap photfavicon ico | indian mature adult breast feeding porn | ameesha patel sex scenes | real brother and real sister rapexxx | 10 foking bf videop xxx tazania video comndian college toilet sex video 3gp nazriyanazim sex video down | 광주오피【010 2411 6522】광주오피ꋠ나주출장마사지㎜광주오피⎢나주출장마사지@담양출장마사지☾나주출장마사지 | middle age aunti malu sex hd nude top sexy gir | wooy2n01clu | p1eqh1n2dty |
<