@BlackHatOfficialYT
  @BlackHatOfficialYT
Black Hat | Smashing the State Machine: The True Potential of Web Race Conditions @BlackHatOfficialYT | Uploaded 9 months ago | Updated 1 hour ago
For too long, web race-condition attacks have focused on a tiny handful of scenarios. Their true potential has been masked thanks to tricky workflows, missing tooling, and simple network jitter hiding all but the most trivial, obvious examples. In this session, I'll introduce multiple new classes of race condition that go far beyond the limit-overrun exploits you're probably already familiar with.

Inside every website lurks a state machine: a delicately balanced system of states and transitions that each user, session, and object can flow through. I'll show how to fire salvos of conflicting inputs to make state machines collapse, enabling you to forge trusted data, misroute tokens, and mask backdoors. These exploits will be demonstrated across multiple high-profile websites, and a certain popular authentication framework....

By: James Kettle

Full Abstract and Presentation Materials: blackhat.com/us-23/briefings/schedule/#smashing-the-state-machine-the-true-potential-of-web-race-conditions-31712
Smashing the State Machine: The True Potential of Web Race ConditionsHacking Your Documentation: Who Should WTFM?When a Zero Day and Access Keys Collide in the Cloud: Responding to the SugarCRM 0-Day VulnerabilityMaking and Breaking NSAs Codebreaker ChallengeEvading Logging in the Cloud: Bypassing AWS CloudTrailFireside Chat: Jeff Moss and Ruimin HeDebug7: Leveraging a Firmware Modification Attack for Remote Debugging of Siemens S7 PLCsMagicdot: A Hackers Magic Show of Disappearing Dots and SpacesIllegitimate Data Protection Requests - To Delete or to Address?IRonMAN: InterpRetable Incident Inspector Based ON Large-Scale Language Model and Association miNingKill Latest MPU-based Protections in Just One Shot: Targeting All Commodity RTOSesUnsafe At Any Speed: CISAs Plan to Foster Tech Ecosystem Security

Smashing the State Machine: The True Potential of Web Race Conditions @BlackHatOfficialYT

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER