DEF CON 32 - Listen to the Whispers: Web Timing Attacks that Actually Work - James Kettle
Websites are riddled with timing oracles eager to divulge their innermost secrets. It's time we started listening to them. In this session, I'll unleash novel attack concepts to coax out server secrets including masked misconfigurations, blind data-structure injection, hidden routes to forbidden areas, and a vast expanse of invisible attack-surface. This is not a theoretical threat; every technique will be illustrated with multiple real-world case studies on diverse targets. Unprecedented advances have made these attacks both accurate and efficient; in the space of ten seconds you can now reliably detect a sub-millisecond differential with no prior configuration or 'lab conditions' required. In other words, I'm going to share timing attacks you can actually use. To help, I'll equip you with a suite of battle-tested open-source tools enabling both hands-free automated exploitation, and custom attack scripting. I'll also share a little CTF to help you hone your new skillset. Want to take things further? I'll help you transform your own attack ideas from theory to reality, by sharing a methodology refined through testing countless concepts on thousands of websites. We've neglected this omnipresent and incredibly powerful side-channel for too long.

DEF CON 33 - Kill List: Hacking an Assassination Site on the Dark Web - Carl Miller, Chris Monteiro

DEF CON 32 - Optical Espionage: Using Lasers to Hear Keystrokes Through Glass Windows - samy kamkar

HTTP Request Smuggling Explained (with James Kettle)

DEF CON 32 - Social Engineering Like you’re Picard - Jayson E Street

Hacking the Hackers: The Art of Compromising C2 Servers with Vangelis Stykas

DEF CON 32 - Anyone can hack IoT- Beginner’s Guide to Hacking Your First IoT Device - Andrew Bellini

how is this hacking tool legal?

DEF CON 33 - Cash, Drugs, and Guns - Why Your Safes Aren't Safe - Mark Omo, James Rowley

Web Cache Entanglement: Novel Pathways to Poisoning - James Kettle (albinowax)

Creator of C++: Bell Labs, Negative Overhead Abstraction, Mistakes | Bjarne Stroustrup

Hacking challenge at DEFCON

DEF CON 23 - Robinson and Mitchell - Knocking my neighbors kids cruddy drone offline

Free Hacking API courses (And how to use AI to help you hack)

Practical Web Cache Poisoning: Redefining 'Unexploitable'

HTTP/2: The Sequel is Always Worse - James Kettle (albinowax)

Cracking the Lens: Targeting HTTP's Hidden Attack-Surface

DEF CON 32 - Gotta Cache ‘em all bending the rules of web cache exploitation - Martin Doyhenard

#NahamCon2024: Modern WAF Bypass Techniques on Large Attack Surfaces

DEF CON 30 - James Kettle - Browser-Powered Desync Attacks: A New Frontier in HTTP Request Smuggling

