The humble web browser is a workhorse of the modern world, and it can get you into some real trouble if you’re not careful.
Security experts know that better than most, and there’s no better place to bone up on the ins and outs of web security than Black Hat Asia in Singapore next month, where a bevy of Briefings, Trainings, and Arsenal tool demos offer loads of opportunities for hands-on learning.
“Who Left Open the Cookie Jar?” is a 50-minute Briefing where researchers Tom Van Goethem and Gertjan Franke will walk you through how several flaws in seven browsers and 46 browser extensions purportedly block third-party cookies.
You want to see this Briefing to learn how the researchers novel techniques can prevent attackers from circumventing many of today’s built-in protection mechanisms. They’ll also show you that for every anti-tracking or ad-blocking browser extension there exists at least one technique to bypass its defenses, then offer a solution and analyze why these bypass techniques exist.
For a different perspective on Web security, check out the 25-minute Briefing on “Make Redirection Evil Again - URL Parser Issues in OAuth.” You’ll get a quick refresher on the security community's understanding of OAuth redirection threats, learn how OAuth has evolved and what the best practices are for implementing it in your own projects.
Now, the fun part: You’ll get a demonstration of new OAuth redirection attack techniques which exploit the interaction of URL parsing problems with redirection handling in mainstream browsers or mobile apps. In particular, some attacks leverage newly-discovered URL interpretation bugs in mainstream browsers or the Android platform. (The latter were independently discovered and have been recently patched.)
Don’t forget to stop by the Black Hat Asia Arsenal (located in the Business Hall) to enjoy some live demos of useful web security tools and chat with the folks who make them. Catch “A Look at ModSec 3.0 for NGINX: A Software Web Application Firewall” on Friday morning to see how at how the popular open-source proxy server NGINX can be combined with the respected open-source web app firewall ModSecurity to create an effective, secure layer for your web application stack.
You can also see the latest version of ModSecurity live during the “ModSecurity 3.1: Stepping up the Game for Web Attacks” Arsenal demo. The 3.1 release promises improved performance, stability and new exciting features including an exclusive testing feature that allows rules writers and WAF administrators to effortlessly search and match for known malware payloads and signatures. Be sure to stop by and check it out!
The result (at least if everything works well) is that you open your browser, wait until the victim visits your website, and then start browsing the internal websites in their network. It’s a great trick (especially if you’re part of a red team), and the best way to see it is to come to Black Hat Asia next month.
Black Hat Asia returns to the Marina Bay Sands in Singapore March 26-29, 2019. For more information on what’s happening at the event and how to register, check out the Black Hat website.