
(Chief Information Security Officer)The first part of the presentation introduces the audience to Padding Oracle Attacks, the cryptographic concepts of the vulnerability, and finally how to exploit it. We also describe the algorithms implemented in POET (Padding Oracle Exploit Tool). POET is the free tool that we released a few months ago which can automatically find and exploit Padding Oracle vulnerabilities in web applications.
The second part presents a previously unknown advanced attack. The most significant new discovery is an universal Padding Oracle affecting every ASP.NET web application. In short, you can decrypt cookies, view states, form authentication tickets, membership password, user data, and anything else encrypted using the framework's API!
Finally we demonstrate the attacks against real world applications. We use the Padding Oracle attack to decrypt data and use CBC-R to encrypt our modifications. Then we abuse components present in every ASP.NET installation to forge authentication tickets and access applications with administration rights. The vulnerabilities exploited affect the framework used by 25% of the Internet websites.The impact of the attack depends on the applications installed on the server, from information disclosure to total system compromise.
Estamos orgullosos de anunciar la octava edición de la ekoparty security conference.Una vez más, e...
A solo días de la edición 2011 de la ekoparty, varios trainings han sido vendidos completamente, y...
El próximo 26 de Julio de 2011, tendrá lugar la jornada solidaria #1HackParaLosChicos, enterate co...
De la mano de IMMUNITY, empresa líder en el desarrollo de aplicaciones para penetration testing, tr...
Tenemos el placer de anunciar, que el Slogan votado por la gente, para representar a la ekoparty 201...
diseño: GrafikaWeb