PortSwigger Research Previews Three Major Security Talks for DEF CON and Black Hat USA
PortSwigger Research has announced three significant cybersecurity presentations scheduled for release at Black Hat USA and DEF CON 32 in August 2024. The sessions, led by researchers James Kettle, Gareth Heyes, and Martin Doyhenard, focus on advanced web security vulnerabilities and exploitation techniques. James Kettle will discuss practical web timing attacks, introducing methods to detect sub-millisecond differentials and uncover server secrets using new open-source tools. Gareth Heyes will explore email parsing vulnerabilities, demonstrating how RFC-compliant addresses can bypass access controls and spoof domains in Zero Trust environments. Martin Doyhenard will present novel web cache exploitation techniques, including Static Path Deception and Cache Key Confusion, which leverage URL parser inconsistencies in major platforms like Microsoft Azure and Cloudflare. Each talk includes accompanying whitepapers, toolkits, and capture-the-flag challenges to help attendees apply these methodologies. This announcement highlights critical advancements in identifying and exploiting side-channel attacks, parser discrepancies, and cache deception, offering valuable insights for security professionals attending these premier industry conferences.
Wire timeline
PortSwigger Research Previews Three Major Security Talks for DEF CON and Black Hat USA
PortSwigger Research has announced three significant cybersecurity presentations scheduled for release at Black Hat USA and DEF CON 32 in August 2024. The sessions, led by researchers James Kettle, Gareth Heyes, and Martin Doyhenard, focus on advanced web security vulnerabilities and exploitation techniques. James Kettle will discuss practical web timing attacks, introducing methods to detect sub-millisecond differentials and uncover server secrets using new open-source tools. Gareth Heyes will explore email parsing vulnerabilities, demonstrating how RFC-compliant addresses can bypass access controls and spoof domains in Zero Trust environments. Martin Doyhenard will present novel web cache exploitation techniques, including Static Path Deception and Cache Key Confusion, which leverage URL parser inconsistencies in major platforms like Microsoft Azure and Cloudflare. Each talk includes accompanying whitepapers, toolkits, and capture-the-flag challenges to help attendees apply these methodologies. This announcement highlights critical advancements in identifying and exploiting side-channel attacks, parser discrepancies, and cache deception, offering valuable insights for security professionals attending these premier industry conferences.
PortSwigger Research