SITH Happens: Attack of Malicious WASMs

No ratings

Presented at BSidesDelhi 2018 by

JavaScript is most popular language of the web. It is one of the fastest dynamic languages around, even though it is fast it still cannot compete with raw C/C++. WebAssembly an evolution of asm.js, is a low level, portable binary format that aims to speed up apps on the order of 20x compared to javascript. In this talk you’ll learn about how WebAssembly works. We look into the dark side of WebAssembly, use of WebAssembly for malicious activities starting with basic tech-scams and key loggers to sophisticated key-loggers. We will look at some malicious and vulnerable WebAssembly modules and highlight some gotchas while writing WASM modules. We hope that you get a good grasp of the WebAssembly threat model and learn what to look for while analyzing WebAssembly modules.