DEF CON 27 - Ben Sadeghipour - Owning The Clout Through Server-Side Request Forgery @HackersOnBoard
DEF CON 27 - Ben Sadeghipour - Owning The Clout Through Server-Side Request Forgery  @HackersOnBoard
Uploaded December 2019 | Updated September 2026, 21 hours ago
With how many apps are running in the cloud, hacking these instances becomes easier with a simple vulnerability due to an unsanitized user input. In this talk, we’ll discuss a number of different methods that helped us exfil data from different applications using Server-Side Request Forgery (SSRF). Using these methods, we were able to hack some of the major transportation, hospitality, and social media companies and make $50,000 in rewards in 3 months.
DEF CON 27 - Ben Sadeghipour - Owning The Clout Through Server-Side Request ForgeryDEF CON 27 - Junyu Zhou - Web2Own Attacking Desktop Apps From Web Securitys PerspectiveDEF CON 27 - Marina Simakov - Relaying Credentials Has Never Been EasierDEF CON 27 - Omer Gull - SELECT code execution FROM USING SQLiteDEF CON 27 - Xiaolong Bai - HackPac Hacking Pointer Authentication in iOS User SpaceDEF CON 27 - Itzik Kotler - Process Injection Techniques Gotta Catch Them AllBlack Hat USA 2018 - Deep Dive into an ICS Firewall, Looking for the Fire HoleDEF CON 27 - Can You Track Me Now? Why The Phone Companies Are Such A Privacy DisasterBlack Hat USA 2018 - How I Learned to Stop Worrying and Love the SBOMBlack Hat USA 2018 - Remotely Attacking System FirmwareBlack Hat USA 2018 - Windows Offender Reverse Engineering Windows Defenders Antivirus EmulatorDEF CON 27 - Joshua Maddux - API-Induced SSRF How Apple Pay Scattered Vulnerabilities Across the Web
HackersOnBoard |

DEF CON 27 - Ben Sadeghipour - Owning The Clout Through Server-Side Request Forgery

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER