DEFCON 18: How I Met Your Girlfriend 2/3

Speaker: Samy Kamkar How I Met Your Girlfriend: The discovery and construction of entire new classes of attacks via the Web to meet your girlfriend. Belong to newly discovered attacks, including HTML5 client-side XSS (no XSS hits the server!), PHP session hijacking and random numbers (just guessing PHP session cookies), browser-protocol confusion (turning a browser into an SMTP server), firewall and NAT penetration via javascript (turning your router against you), kidnapping Remote iPhone Google Maps (iPhone penetration in combination with HTTP man-in-the-middle), extraction means extremely precise geolocation information from a Web browser (not using IP Geolocation ) and much more. For presentations, white papers or audio version of the Defcon 18 presentations can be found at: defcon.org
Video Rating: 4 / 5

VN:F [1.9.4_1102]
Rating: 0.0/10 (0 votes cast)
VN:F [1.9.4_1102]
Rating: 0 (from 0 votes)

Related Posts:

You can leave a response, or trackback from your own site.

16 Responses to “DEFCON 18: How I Met Your Girlfriend 2/3”

  1. ImCapn says:

    Oh god, he’s a /b/tard.

    VA:F [1.9.4_1102]
    Rating: 0.0/5 (0 votes cast)
    VA:F [1.9.4_1102]
    Rating: 0 (from 0 votes)
  2. mourantell says:

    @iFynni C’mon everyone gets it since “at leat 100 years ago”

    VA:F [1.9.4_1102]
    Rating: 0.0/5 (0 votes cast)
    VA:F [1.9.4_1102]
    Rating: 0 (from 0 votes)
  3. southparkfanatic101 says:

    I just tried to friend him on facebook. I hope I am not fucked now.

    VA:F [1.9.4_1102]
    Rating: 0.0/5 (0 votes cast)
    VA:F [1.9.4_1102]
    Rating: 0 (from 0 votes)
  4. xt3nt says:

    30k views and no dislikes. nice.

    VA:F [1.9.4_1102]
    Rating: 0.0/5 (0 votes cast)
    VA:F [1.9.4_1102]
    Rating: 0 (from 0 votes)
  5. antipryzm says:

    lol @ the hackers movie stuff.

    VA:F [1.9.4_1102]
    Rating: 0.0/5 (0 votes cast)
    VA:F [1.9.4_1102]
    Rating: 0 (from 0 votes)
  6. asciistudios says:

    @jcald89 nope, the irc I’m on is 6677

    VA:F [1.9.4_1102]
    Rating: 0.0/5 (0 votes cast)
    VA:F [1.9.4_1102]
    Rating: 0 (from 0 votes)
  7. iFynni says:

    LOL, no one gets the OVER 9000 Joke :D

    VA:F [1.9.4_1102]
    Rating: 0.0/5 (0 votes cast)
    VA:F [1.9.4_1102]
    Rating: 0 (from 0 votes)
  8. Snprwlf says:

    wow, samy is like the beautiful mind if it comes to exploits

    VA:F [1.9.4_1102]
    Rating: 0.0/5 (0 votes cast)
    VA:F [1.9.4_1102]
    Rating: 0 (from 0 votes)
  9. sootianag says:

    @jcald89 I think he was referring to 11:20 when he quotes routers that you “shouldn’t be running a web server on port 6667.”

    VA:F [1.9.4_1102]
    Rating: 0.0/5 (0 votes cast)
    VA:F [1.9.4_1102]
    Rating: 0 (from 0 votes)
  10. gumpdy says:

    Theoretically: If you were the owner of several massively visited websites, could you use this method to use people’s browsers to DDoS?

    VA:F [1.9.4_1102]
    Rating: 0.0/5 (0 votes cast)
    VA:F [1.9.4_1102]
    Rating: 0 (from 0 votes)
  11. andrewe323 says:

    If you pay attention, the crowd stfu b/c the guy starts droppin’ real shit…

    This reduction method works for a lot of shit

    VA:F [1.9.4_1102]
    Rating: 0.0/5 (0 votes cast)
    VA:F [1.9.4_1102]
    Rating: 0 (from 0 votes)
  12. philds391 says:

    @canucks16 Can you ask the people in the back to shut up?

    VA:F [1.9.4_1102]
    Rating: 0.0/5 (0 votes cast)
    VA:F [1.9.4_1102]
    Rating: 0 (from 0 votes)
  13. canucks16 says:

    what does the guy say at 8:10 ?

    VA:F [1.9.4_1102]
    Rating: 0.0/5 (0 votes cast)
    VA:F [1.9.4_1102]
    Rating: 0 (from 0 votes)
  14. jcald89 says:

    @goten1201 Running the web server on 6667 is required so that the router assumes that the web server is an IRC server. Read the slide at 8:10. This is not “best practices”, this is hacking.

    VA:F [1.9.4_1102]
    Rating: 0.0/5 (0 votes cast)
    VA:F [1.9.4_1102]
    Rating: 0 (from 0 votes)
  15. goten1201 says:

    You shouldn’t use 6667 If you’re running a webserver on that, You’re stupid, change your port.

    VA:F [1.9.4_1102]
    Rating: 0.0/5 (0 votes cast)
    VA:F [1.9.4_1102]
    Rating: 0 (from 0 votes)
  16. fusionet24 says:

    Amazing

    VA:F [1.9.4_1102]
    Rating: 0.0/5 (0 votes cast)
    VA:F [1.9.4_1102]
    Rating: 0 (from 0 votes)

Leave a Reply