Who Is Your Parser And What Does He Do: URL Parsing Gone Wrong

Who Is Your Parser And What Does He Do: URL Parsing Gone Wrong

説明:

Understanding URLs is hard, parsing them is even harder. When we compared different URL parsers, we found that the results varied from one parser to another. That sparked our curiosity and led us to compare URL parsers across different platforms and programming languages. In our presentation, we will discuss numerous exploitation techniques that use URL parsing inconsistencies, as well as some vulnerabilities we've discovered in popular open-source projects used by many applications.

講演者:

Noam Moshe

Security Researcher, undefined

Snyk (スニーク) は、デベロッパーセキュリティプラットフォームです。Snyk は、コードやオープンソースとその依存関係、コンテナや IaC (Infrastructure as a Code) における脆弱性を見つけるだけでなく、優先順位をつけて修正するためのツールです。世界最高峰の脆弱性データベースを基盤に、Snyk の脆弱性に関する専門家としての知見が提供されます。

無料で始める資料請求

© 2024 Snyk Limited
Registered in England and Wales

logo-devseccon