Who Is Your Parser And What Does He Do: URL Parsing Gone Wrong

Who Is Your Parser And What Does He Do: URL Parsing Gone Wrong

Beschreibung:

Understanding URLs is hard, parsing them is even harder. When we compared different URL parsers, we found that the results varied from one parser to another. That sparked our curiosity and led us to compare URL parsers across different platforms and programming languages. In our presentation, we will discuss numerous exploitation techniques that use URL parsing inconsistencies, as well as some vulnerabilities we've discovered in popular open-source projects used by many applications.

Speaker:

Noam Moshe

Security Researcher, undefined

Patch Logo SegmentPatch Logo SegmentPatch Logo SegmentPatch Logo SegmentPatch Logo SegmentPatch Logo SegmentPatch Logo SegmentPatch Logo SegmentPatch Logo SegmentPatch Logo SegmentPatch Logo SegmentPatch Logo SegmentPatch Logo Segment

Snyk ist eine Developer Security Plattform. Integrieren Sie Snyk in Ihre Tools, Workflows und Pipelines im Dev-Prozess – und Ihre Teams identifizieren, priorisieren und beheben Schwachstellen in Code, Abhängigkeiten, Containern, Cloud-Ressourcen und IaC nahtlos. Snyk bringt branchenführende Application & Security Intelligence in jede IDE.

Kostenlos startenLive-Demo buchen

© 2024 Snyk Limited
Alle Rechte vorbehalten

logo-devseccon