Skip to content

Latest commit

 

History

History
83 lines (42 loc) · 4.45 KB

2015.md

File metadata and controls

83 lines (42 loc) · 4.45 KB

Web Hacking Techniques 2015

LogJam

Abusing XSLT for Practical Attacks

Java Deserialization w/ Apache Commons Collections in WebLogic, WebSphere, JBoss, Jenkins, and OpenNMS

Breaking HTTPS with BGP Hijacking

Pawn Storm (CVE-2015-7645)

Superfish SSL MitM

Bypass Surgery

Abusing CDNs with SSRF Flash and DNS

Google Drive SSO Phishing

Dom Flow

Untangling The DOM For More Easy-Juicy Bugs

Password mining from AWS/Parse Tokens

St. Louis Federal Reserve DNS Redirect

Exploiting XXE in File Upload Functionality

Expansions on FREAK attack

eDellRoot

WordPress Core RCE

FileCry

The New Age of XXE

Server-Side Template Injection: RCE for the Modern Web App

IE11 RCE

Understanding and Managing Entropy Usage

Attack Surface for Project Spartan's EdgeHTML Rendering Engine

Web Timing Attacks Made Practical

Winning the Online Banking War

CNNINC SSL MitM

New Methods in Automated XSS Detection: Dynamic XSS Testing Without Using Static Payloads Practical Timing Attacks using Mathematical Amplification of Time Difference in == Operator

The old is new, again. CVE20112461 is back!

illusoryTLS

Hunting ASynchronous Vulnerabilities

New Evasions for Web Application Firewalls

Magic Hashes

Formaction Scriptless attack updates

The Unexpected Dangers of Dynamic JavaScript

Who Are You? A Statistical Approach to Protecting LinkedIn Logins(CSS UI Redressing Issue)

Evading All Web Application filters

Multiple Facebook Messenger CSRF's

Relative Path Overwrite

SMTP Injection via Recipient Email Address

Serverside Template Injection

Hunting Asynchronous Vulnerabilities