Загрузка страницы

Portable Data exFiltration XSS for PDFs - Gareth Heyes

Gareth Heyes presents his latest research - Portable Data exFiltration XSS for PDFs. This is the director's cut of the presentation that premiered at Black Hat Europe on December 10th, 2020. Read the full whitepaper: https://portswigger.net/research/portable-data-exfiltration

PDF documents and PDF generators are ubiquitous on the web, and so are injection vulnerabilities. Did you know that controlling a measly HTTP hyperlink can provide a foothold into the inner workings of a PDF? In this session, you will learn how to use a single link to compromise the contents of a PDF and exfiltrate it to a remote server, just like a blind XSS attack.

Resources:
https://insert-script.blogspot.com/2015/05/pdf-mess-with-web.html
https://speakerdeck.com/ange/lets-write-a-pdf-file
https://docs.google.com/presentation/d/1JdIjHHPsFSgLbaJcHmMkE904jmwPM4xdhEuwhy2ebvo/htmlpresent

Видео Portable Data exFiltration XSS for PDFs - Gareth Heyes канала PortSwigger
Показать
Комментарии отсутствуют
Введите заголовок:

Введите адрес ссылки:

Введите адрес видео с YouTube:

Зарегистрируйтесь или войдите с
Информация о видео
11 декабря 2020 г. 19:00:07
00:31:21
Яндекс.Метрика