#Hacktivity2024 // Exploiting Hidden Semantic Ambiguity in Apache HTTP Server!
Orange Tsai -Confusion Attacks: Exploiting Hidden Semantic Ambiguity in Apache HTTP Server! This presentation was held at #Hacktivity2024 IT security conference on 14th October 2024. Apache HTTP Server, as a cornerstone of the entire World Wide Web, accounts for about one-third of the web server market share worldwide. It's not an overstatement to say that its security is synonymous with the security of the Internet. However, while delving into the source by chance, we discovered that the coding style of this open-source project seemed a little bit... open? This research was thus born! The Apache Httpd is comprised of dozens of different modules, which are coupled together. When a new HTTP request arrives, all modules uphold and maintain a colossal structure, collaborating in harmony to complete the request. While this cooperation might sound ideal, the reality reveals a significant challenge: the modules are not entirely familiar with each other, especially regarding the implementation details. However, they are asked to collaborate to fulfill the task. If any module has an incorrect understanding of any fields of this huge structure, it could potentially lead to fatal issues. This observation led us to focus on interactions between modules, and discover this new attack surface. Let's see how a seemingly harmless structure modification can be passed through layers, amplifying the impact and affecting other modules to become vulnerabilities. This novel attack surface unearthed 3 distinct types of Confusion Attacks and 8 vulnerabilities, which allow us to navigate easily between Httpd modules, generating various attacks based on the different functionalities of modules: from the simplest arbitrary source code disclosure to misinterpreting a normal image as malicious scripts, bypassing ACL, and enabling unlimited SSRF. Of course, we won't forget about RCE, we will demonstrate how a long-underestimated bug type can be transformed into code execution by leveraging Httpd's internal features! By understanding this talk, attendees won't be surprised at how we've managed to teach an old dog new tricks. Developers will understand how to avoid writing problematic Httpd modules. Server Admins can utilize this knowledge to examine their sites for potential vulnerabilities, and security researchers are able to explore more hidden issues along this direction. It's a scenario where everyone wins! https://www.hacktivity.com #cybersecurity #apache #exploit

Attacking AI - Jason Haddix - NDC Security 2026

Let’s Handle 1 Million Requests per Second, It’s Scarier Than You Think!
![Nicholas Carlini - Black-hat LLMs | [un]prompted 2026](https://i.ytimg.com/vi/1sd26pWhfmg/hqdefault.jpg?sqp=-oaymwE9CNACELwBSFryq4qpAy8IARUAAAAAGAElAADIQj0AgKJDeAHwAQH4Af4JgALQBYoCDAgAEAEYciBmKDYwDw==&rs=AOn4CLBn1sRfbeYcMnkqD2mtRZhq1TO6JQ)
Nicholas Carlini - Black-hat LLMs | [un]prompted 2026

#Hacktivity2023 // It Was Harder to Sniff Bluetooth Through My Mask During the Pandemic…

THC 2026 - Michael Schwarz Keynote

#Hacktivity2024 // Hacking CS:GO to Death

Something is jamming GPS over Europe. Here's what we found

How to Track the People Tracking YOU

I Became The Most FEARED WARLORD Of This Minecraft SMP

HOLY ROSARY TODAY THURSDAY, JUNE 11, 2026 ST. JUDE THADDEUS & LUMINOUS MYSTERIES | DAILY HOLY ROSARY

How to Get and Evaluate Startup Ideas | Startup School

#Hacktivity2024 // The Dual-Edged Sword of AI

#Hacktivity2023 // API Security Assurance via E2E Testing

AI Security Landscape - Tales and Techniques from the Frontlines

God Says:"STOP HERE — LISTEN AND HEAR ME SPEAK"/God Message Now/God Message

Harder Drive: Hard drives we didn't want or need

#Hacktivity2023 // Examining the Explanatory Factors of Malicious Hacking Behaviors

#Hacktivity2023 // Can We Break the Fault Injection Mitigation Bob?

Backend web development - a complete overview

