One More Weakness in Modern Client-Server Applications

No ratings

Presented at phdays 2013 by

The speaker will present a post-exploitation technique which allows you to hack your favorite application server and get sensitive information through pwned client and at the same time bypass firewall restrictions, leave no trace in logs and bypass many-factor authentication to exfiltrate a lot of private data. Did you hear about modern techniques utilized by Caberp or Zeus to hijack banking apps and bypass two-factor authentications and other security features? The speaker will raise them to the level of enterprise applications such as Oracle DBMS or similar. Anton Sapozhnikov has more than 6 years of experience in penetration testing. He worked with many companies from Fortune Global 500 list. In his spare time he participates in CTFs with More Smocked Leet Chicken. Moscow, RussiaAnton Sapozhnikov Anton Sapozhnikov