BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Reflections on Disregarding Trust (Weaponizing CDP a
 nd MHTML\n   for Header-Agnostic Session Hijacking)\n   Tags: DEF CON Offi
 cial Talk | Demo ðŸ’» | Tool ðŸ›  | Exploit ðŸª²\n   When: Friday\, Aug 7\
 , 10:30 - 11:30 PDT\n   Where: LVCCW Level 1 Hall 3 904 (Main Track 4) and
  DCTV-4 - [1]Map\n\n   Description:\n\n   Adversary-in-the-Middle (AitM) p
 hishing has become the de facto\n   standard for bypassing legacy Multi-Fa
 ctor Authentication (MFA).\n   However\, modern AitM frameworks rely on co
 mplex\, fragile regex rules\n   to rewrite HTTP streams on the fly. When t
 arget applications implement\n   strict client-side security headers like 
 Subresource Integrity (SRI)\n   and Content Security Policy (CSP)\, tradit
 ional proxies break\, alerting\n   defenders.\n\n   This presentation intr
 oduces a novel "Browser-in-the-Middle"\n   architecture. By weaponizing th
 e Chrome DevTools Protocol (CDP)\, this\n   custom-built Go toolkit render
 s the target application server-side\,\n   allows legitimate scripts to ex
 ecute\, and captures the resulting DOM\n   as an MHTML snapshot. I will de
 monstrate how converting external\n   assets into Base64 Data URIs and ser
 ving a self-contained\, live DOM\n   neutralizes SRI and CSP organically w
 ithout triggering browser\n   security violations. Finally\, the talk will
  detail a Just-In-Time\n   (JIT) JavaScript shim that hooks API calls to s
 ilently harvest\n   post-MFA tokens from major IdPs including Okta\, Micro
 soft\, Google\, and\n   Shibboleth effectively trapping the user in a perf
 ectly mirrored\,\n   attacker-controlled environment.\n\n   SpeakerBio:  G
 regory "1umberhack" Disney-Leugers\, Independent\n   Researcher\n\n   Greg
 ory Disney-Leugers (1umberhack) is a Independent Researcher\n   specializi
 ng in adversary simulation\, modern web authentication\n   bypasses\, and 
 identity-based attacks. With over a decade of experience\n   in red teamin
 g and penetration testing since 2013\, they have\n   previously served as 
 a Technical Lead at major technology and identity\n   providers\, includin
 g Juniper Networks and Okta.\n\n   '\n\n   1. #LVCCW_Level1_Hall3\n\n\n
DTEND:20260807T183000Z
DTSTART:20260807T173000Z
LOCATION:DEF CON Talks - LVCCW Level 1 Hall 3 904 (Main Track 4) and DCTV-4
SUMMARY:Reflections on Disregarding Trust (Weaponizing CDP and MHTML for He
 ader-Agnostic Session Hijacking)
END:VEVENT
END:VCALENDAR
