BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Gotta Cache ‘em all: bending the rules of web cach
 e\n   exploitation\n   When: Saturday\, Aug 10\, 10:30 - 11:15 PDT\n   Whe
 re: LVCC West/Floor 1/Hall 1/Track 2 - [1]Map\n\n   Description:\n\n   In 
 recent years\, web cache attacks have become a popular way to steal\n   se
 nsitive data\, deface websites\, and deliver exploits. We've also seen\n  
  parser inconsistencies causing critical vulnerabilities like HTTP\n   Req
 uest Smuggling. This raises the question: what happens if we attack\n   we
 b caches' URL-parsers?\n\n   In this session\, I'll introduce two powerful
  new techniques that\n   exploit RFC ambiguities to bypass the limitations
  of web cache\n   deception and poisoning attacks.\n\n   First\, I'll intr
 oduce Static Path Deception\, a novel technique to\n   completely compromi
 se the confidentiality of an application. I’ll\n   illustrate this with 
 a case study showing how such a breach can be\n   replicated in environmen
 ts like Nginx behind Cloudflare.\n\n   Next\, I'll present Cache Key Confu
 sion\, and show how to exploit URL\n   parsing inconsistencies in major pl
 atforms\, including Microsoft Azure\n   Cloud. I’ll then show how to ach
 ieve arbitrary cache poisoning and\n   full denial of service.\n\n   Final
 ly\, I'll reveal how to supercharge these vulnerabilities with a\n   live 
 demo that blends Cache Key Confusion with a “non-exploitable”\n   open
  redirect to execute arbitrary JS code for complete site takeover.\n\n   A
 ttendees will depart armed with a set of innovative techniques\, along\n  
  with a definitive methodology to find and exploit these and other URL\n  
  or HTTP discrepancies.\n\n   Web Cache Deception Attack - Omer Gil [2]lin
 k\n\n   This is the first time Web Cache Deception attacks were introduced
  and\n   worked as a starting point for my research.\n\n   Web Cache Entan
 glement: Novel Pathways to Poisoning - James Kettle [3]link\n\n   This res
 earch worked as an inspiration to develop the cache poisoning\n   techniqu
 es. I also used this paper to outline the state of the art in\n   web cach
 e exploitation and create a different approach using parser\n   discrepanc
 ies.\n\n   Cached and confused: Web cache deception in the wild - Seyed Al
 i\n   Mirheidari\, Sajjad Arshad\, Kaan Onarlioglu\, Bruno Crispo\, Engin 
 Kirda\n   and William Robertson. [4]link\n\n   The web cache deception tec
 hniques using delimiters for path confusion\n   were inspired by the 2020 
 USENIX presentation “Cached and confused:\n   Web cache deception in the
  wild”. In that presentation\, they briefly\n   describe some variations
  of path confusion using four encoded\n   characters. Although the objecti
 ve of their paper was to show a\n   large-scale study of web cache decepti
 on vulnerabilities in the wild\,\n   it also introduced the use of delimit
 ers for path confusion. In my\n   presentation I'll expand on this concept
 \, providing a methodology to\n   find all the delimiters used by a URL pa
 rser and explaining how to use\n   them in new exploitation techniques.\n\
 n   ChatGPT Account Takeover - Wildcard Web Cache Deception - Harel\n   Se
 curity Research [5]link\n\n   Also\, during the time this research was bei
 ng conducted\, a\n   vulnerability using a single variation of one of the 
 techniques\n   (Static Path Confusion) was published as a write up.\n\n   
 SpeakerBio:  Martin Doyhenard\, Security Researcher at Portswigger\n\n   M
 artin Doyhenard is a Security Researcher at Portswigger\, known for\n   ex
 ploiting HTTP servers and web applications. Over the past few years\n   he
  has presented his findings in multiple top security conferences\n   inclu
 ding BlackHat\, DEFCON\, RSA\, EkoParty\, Hack in The Box and\n   Troopers
 .\n\n   His latest work includes discovering HTTP Response Smuggling\n   t
 echniques and exploiting SAP’s Inter-Process Communication service\n   -
  compromising more than 200 thousand companies in the world.He’s\n   als
 o passionate about low level reverse engineering and testing his\n   skill
 s in online CTFs.\n\n   '\n\n   1. #LVCCW_Level1_Hall1\n   2. https://www.
 blackhat.com/docs/us-17/wednesday/us-17-Gil-Web-Cache-Deception-Attack-wp.
 pdf\n   3. https://portswigger.net/research/web-cache-entanglement\n   4. 
 https://www.usenix.org/system/files/sec20-mirheidari.pdf\n   5. https://no
 kline.github.io/bugbounty/2024/02/04/ChatGPT-ATO.html\n\n\n
DTEND:20240810T181500Z
DTSTART:20240810T173000Z
LOCATION:DC - LVCC West/Floor 1/Hall 1/Track 2
SUMMARY:Gotta Cache ‘em all: bending the rules of web cache exploitation
END:VEVENT
END:VCALENDAR
