Inglourious Hackerds: Targeting Web Clients presented at BlackHatDC 2011

by Laurent Oudot,


Summary : This talk will propose to look at technical security issues related to multiple Internet Web Clients.
While such tools are used to crawl the Net and retrieve information, there might exist many scenarios where evil attackers can abuse them.
By studying the protocols (HTTP, etc), and by doing some kind of fuzzing operations, we will show how TEHTRI-Security was able to find multiple security issues on many handled devices and workstations.
The offensive concepts explained during this talk, will show many different tricks, like how evil attackers can become anonymous and create cover channels based on web clients, or like how to own or crash most famous current web clients and devices.