BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: CRLF-Powered Desync Attacks: Beheading HTTP streams\
 n   Tags: DEF CON Official Talk | Demo đź’» | Tool đź›  | Exploit đźŞ˛\n  
  When: Saturday\, Aug 8\, 17:00 - 17:59 PDT\n   Where: LVCCW Level 1 Hall 
 3 906 (Main Track 3) and DCTV-3 - [1]Map\n\n   Description:\n\n   Have you
  ever discovered a header injection vulnerability and settled\n   for litt
 le more than an open redirect or XSS? In this session\, we\n   introduce a
  battle-tested â€śheader injectionâ€ť powered desync\n   methodology\, ena
 bling you to perform HTTP request smuggling attacks\n   against even stric
 tly RFC-compliant proxy chains.\n\n   We will begin by explaining a well-k
 nown but overlooked CRLF injection\n   primitive that produced HTTP Reques
 t Splitting inside the core\n   infrastructure of a major CDN\, resulting 
 in the capture of live\n   usersâ€™ credentials across thousands of compro
 mised applications.\n\n   Building upon this\, weâ€™ll demonstrate how hea
 der injections can be\n   used to exploit more traditional smuggling attac
 k classes\, even when\n   no parser discrepancy exists. Finally weâ€™ll re
 veal how you can shift\n   previously non-compliant desync attacks into th
 e browser\, unlocking a\n   plethora of novel exploitation opportunities e
 ven when keep-alive\n   connections are not shared between users. The resu
 lt is a slew of\n   real-word case studies with impacts ranging from accou
 nt takeovers via\n   desync-enabled XSS gadgets to cache poisoning\, respo
 nse queue\n   poisoning\, access control bypasses\, and in several cases t
 he\n   possibility of creating the ever-terrifying desync worm.\n\n   Fina
 lly\, weâ€™ll release two open source tools that introduce robust\n   dete
 ction of header injection.\n\n   Speakers:Tom "t0xodile" Stacey\,Tobia "ma
 stersplinter" Righi\n\n   SpeakerBio:  Tom "t0xodile" Stacey\, Independent
 \n\n   Tom 't0xodile' Stacey is a security researcher at PortSwigger with 
 a\n   passion for automating the ideas that "will never work" to find gaps
 \n   in the industry's current understanding of web security. He is best\n
    known for his work in discovering and exploiting underappreciated\n   f
 orms of desync attacks.\n\n   At PortSwigger he spends most of his time ex
 perimenting with the HTTP\n   protocol and the vulnerabilities that arise 
 due to the disagreements\n   between web servers and components with the g
 oal of finding novel\n   techniques to improve Burp Suite's capabilities. 
 When he's not at\n   work\, he's usually playing some form of video / boar
 d game or building\n   Lego.\n\n   SpeakerBio:  Tobia "mastersplinter" Rig
 hi\, TurtleSec\n\n   I am a security research and bug bounty hunter\, rece
 ntly I have\n   started TurtleSec with other talented hackers\, focusing o
 n research\n   driven projects. I spend most of my time tinkering with app
 lications\n   to try and figure out how to break them in the weirdest of w
 ays.\n\n   '\n\n   1. #LVCCW_Level1_Hall3\n\n\n
DTEND:20260809T005900Z
DTSTART:20260809Z
LOCATION:DEF CON Talks - LVCCW Level 1 Hall 3 906 (Main Track 3) and DCTV-3
SUMMARY:CRLF-Powered Desync Attacks: Beheading HTTP streams
END:VEVENT
END:VCALENDAR
