How I Met Your Girlfriend presented at SecTor 2010

by Samy Kamkar,

Summary : How I Met Your Girlfriend: The discovery and execution of entirely new classes of Web attacks in order to meet your girlfriend. This includes entertaining and newly discovered attacks including PHP session prediction and random numbers (accurately guessing PHP session cookies), browser protocol confusion (turning a browser into an SMTP server), firewall and NAT penetration via Javascript (turning your router against you), extracting extremely accurate geolocation information from a Web browser (not using IP geolocation), and more.