Skip to content

Consolidated demo and source links from Bryant Zadegan and Ryan Lester's Black Hat / DEF CON talk "Abusing Bleeding Edge Web Standards for AppSec Glory".

Notifications You must be signed in to change notification settings

cyph/appsec-glory

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

6 Commits
 
 

Repository files navigation

To see the techniques discussed (including in-browser code signing) implemented in production, check out Cyph.

Slides: us-16-Zadegan-Abusing-Bleeding-Edge-Web-Standards-For-AppSec-Glory.pdf

Video: youtu.be/fFdGnJc0EbM

Demo links:

Source code links:


Edit: After the Black Hat version of our talk on 2016-08-03, it was conveyed to us by Blue Coat that their cert has a path length of 0, thus preventing its use in any sort of wide-ranged HPKP Suicide attack as we'd suggested on stage. We haven't yet thoroughly investigated the implications of path length 0, so feel free to investigate on your own and pass on any findings.

About

Consolidated demo and source links from Bryant Zadegan and Ryan Lester's Black Hat / DEF CON talk "Abusing Bleeding Edge Web Standards for AppSec Glory".

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published