| Date |
Type |
Title |
Author |
Event |
| September 14, 2011 |
Paper |
How I Met Your Girlfriend
|
Samy Kamkar
|
Black Hat USA 2010 |
| September 14, 2011 |
Slides |
How I Met Your Girlfriend
|
Samy Kamkar
|
Black Hat USA 2010 |
| September 13, 2011 |
Paper |
Constricting the Web: Offensive Python for Web Hackers
|
Marcin Wielgoszewski
Nathan Hamiel
|
Black Hat USA 2010 |
| September 13, 2011 |
Slides |
Constricting the Web: Offensive Python for Web Hackers
|
Marcin Wielgoszewski
Nathan Hamiel
|
Black Hat USA 2010 |
| September 11, 2011 |
Paper |
HTTPS Can Byte Me
|
Josh Sokol
Robert 'Rsnake' Hansen
|
Black Hat USA 2010 |
| August 28, 2011 |
Video |
GlastopfNG - A web attack honeypot
|
Sven Vetsch
|
Hashdays 2010 |
| August 28, 2011 |
Slides |
GlastopfNG - A web attack honeypot
|
Sven Vetsch
|
Hashdays 2010 |
| August 19, 2011 |
Video |
CARAT - Configuration And Risk Assessment Toolkit, Metasploit within the Enterprise
|
Max Moser
Philipp Schrödel
|
Hashdays 2010 |
| May 21, 2011 |
Slides |
Black Ops 2007: Design Reviewing The Web
|
Dan Kaminsky
|
Black Hat USA 2007 |
| May 15, 2011 |
Paper |
The Little Hybrid Web Worm that Could
|
Billy Hoffman
John Terrill
|
Black Hat USA 2007 |
| April 18, 2011 |
Slides |
Lifting the Fog
|
|
Black Hat Abu Dhabi 2010 |
| February 20, 2011 |
Audio |
Black Ops Of Fundamental Defense: Web Edition
|
Dan Kaminsky
|
DEFCON 18 |
| February 20, 2011 |
Video |
Black Ops Of Fundamental Defense: Web Edition
|
Dan Kaminsky
|
DEFCON 18 |
| January 12, 2011 |
Slides |
CARAT - Configuration And Risk Assessment Toolkit, Metasploit within the Enterprise
|
Max Moser
Philipp Schrödel
|
Hashdays 2010 |
| November 14, 2010 |
Video |
Something New Something Web Something Not Security
|
|
PhreakNIC 13 |
| November 05, 2010 |
Slides |
Layering in defense: Front ending WWW
|
Erik Berls
|
LayerOne 2005 |
| October 18, 2010 |
Slides |
Analyzing Massive Web Attacks
|
Laurent Oudot
|
Hack In The Box 2010 Malaysia |
| October 05, 2010 |
Slides |
Web Security Going Nowhere
|
Saumil Shah
|
Hack In The Box 2010 Dubai |
| August 13, 2010 |
Audio |
Dissecting Web Attacks
|
Colin Ames
Val Smith
|
Black Hat DC 2009 |
| August 13, 2010 |
Video |
Dissecting Web Attacks
|
Colin Ames
Val Smith
|
Black Hat DC 2009 |
| July 07, 2010 |
Video |
Get Rich or Die Trying - "Making Money on The Web, The Black Hat Way"
|
Jeremiah Grossman
Trey Ford
|
Black Hat USA 2008 |
| July 06, 2010 |
Audio |
Get Rich or Die Trying - "Making Money on The Web, The Black Hat Way"
|
Jeremiah Grossman
Trey Ford
|
Black Hat USA 2008 |
| July 06, 2010 |
Slides |
Get Rich or Die Trying - "Making Money on The Web, The Black Hat Way"
|
Jeremiah Grossman
Trey Ford
|
Black Hat USA 2008 |
| June 05, 2010 |
Slides |
The Fine Art of Hari Kari (.JS), And Other Approaches For The Strange Reality Of Web Defense
|
Dan Kaminsky
|
Source Conference Boston 2010 |
| April 27, 2010 |
Video |
Screen Scraper Tricks: Extracting Data from Difficult Websites
|
Michael Schrenk
|
DEFCON 17 |
| April 27, 2010 |
Slides |
Screen Scraper Tricks: Extracting Data from Difficult Websites
|
Michael Schrenk
|
DEFCON 17 |
| April 27, 2010 |
Audio |
Screen Scraper Tricks: Extracting Data from Difficult Websites
|
Michael Schrenk
|
DEFCON 17 |
| April 13, 2010 |
Video |
Weaponizing the Web: New Attacks on User-generated Content
|
Shawn Moyer
Nathan Hamiel
|
DEFCON 17 |
| April 13, 2010 |
Audio |
Weaponizing the Web: New Attacks on User-generated Content
|
Shawn Moyer
Nathan Hamiel
|
DEFCON 17 |
| February 21, 2010 |
Video |
Unmasking You
|
Robert 'Rsnake' Hansen
Joshua 'Jabra' Abraham
|
DEFCON 17 |
| February 21, 2010 |
Audio |
Unmasking You
|
Robert 'Rsnake' Hansen
Joshua 'Jabra' Abraham
|
DEFCON 17 |
| February 21, 2010 |
Slides |
Unmasking You
|
Robert 'Rsnake' Hansen
Joshua 'Jabra' Abraham
|
DEFCON 17 |
| January 17, 2010 |
Video |
A Tale of Two Proxies
|
|
DEFCON 14 |
| January 17, 2010 |
Audio |
A Tale of Two Proxies
|
|
DEFCON 14 |
| January 01, 2010 |
Slides |
Revealing the Secrets: Source Code Disclosure, Techniques and Impacts
|
Anant Kochar
|
ClubHack2009 |
| January 01, 2010 |
Slides |
Lust 2.0 – Desire for free WiFi and the threat of the Imposter
|
Lavakumar Kuppan
|
ClubHack2009 |
| December 14, 2009 |
Audio |
The SOA/XML Threat Model and New XML/SOA/Web 2.0 Attacks & Threats
|
Steve Orrin
|
DEFCON 15 |
| December 11, 2009 |
Audio |
Comparing Application Security Tools
|
Edward Lee
|
DEFCON 15 |
| December 10, 2009 |
Audio |
HoneyJax (AKA Web Security Monitoring and Intelligence 2.0)
|
Dan Hubbard
|
DEFCON 15 |
| November 04, 2009 |
Audio |
Grendel-Scan: A new web application scanning tool
|
David Byrne
Eric Duprey
|
DEFCON 16 |
| September 09, 2009 |
Paper |
Weaponizing the Web: More Attacks on User-Generated Content
|
Shawn Moyer
Nathan Hamiel
|
Black Hat USA 2009 |
| September 09, 2009 |
Slides |
Weaponizing the Web: More Attacks on User-Generated Content
|
Shawn Moyer
Nathan Hamiel
|
Black Hat USA 2009 |
| September 08, 2009 |
Slides |
Mo' Money Mo' Problems: Making A LOT More Money on the Web the Black Hat Way
|
Jeremiah Grossman
Trey Ford
|
Black Hat USA 2009 |
| September 06, 2009 |
Slides |
Gizmo: A Lightweight Open Source Web Proxy
|
Rachel Engel
|
Black Hat USA 2009 |
| September 06, 2009 |
Paper |
Gizmo: A Lightweight Open Source Web Proxy
|
Rachel Engel
|
Black Hat USA 2009 |
| July 03, 2009 |
Video |
The SOA/XML Threat Model and New XML/SOA/Web 2.0 Attacks & Threats
|
Steve Orrin
|
DEFCON 15 |
| July 03, 2009 |
Slides |
The SOA/XML Threat Model and New XML/SOA/Web 2.0 Attacks & Threats
|
Steve Orrin
|
DEFCON 15 |
| June 25, 2009 |
Slides |
Remote Rootshell on a SOHO Router
|
Michał Sajdak
|
Confidence 2009 Krakow |
| June 25, 2009 |
Slides |
I thought you were my friend Malicious markup, browser issues and other obscurities
|
Mario Heiderich
|
Confidence 2009 Krakow |
| June 23, 2009 |
Video |
Social Attacks on Anonymity Networks
|
Nick Mathewson
|
DEFCON 15 |
| June 20, 2009 |
Paper |
Pretty-Bad-Proxy: An Overlooked Adversary in Browsers’ HTTPS Deployments
|
|
|
| June 20, 2009 |
Slides |
Pretty-Bad-Proxy: An Overlooked Adversary in Browsers’ HTTPS Deployments
|
|
|
| June 18, 2009 |
Video |
Comparing Application Security Tools
|
Edward Lee
|
DEFCON 15 |
| June 18, 2009 |
Slides |
Comparing Application Security Tools
|
Edward Lee
|
DEFCON 15 |
| June 16, 2009 |
Video |
HoneyJax (AKA Web Security Monitoring and Intelligence 2.0)
|
Dan Hubbard
|
DEFCON 15 |
| June 16, 2009 |
Slides |
HoneyJax (AKA Web Security Monitoring and Intelligence 2.0)
|
Dan Hubbard
|
DEFCON 15 |
| May 30, 2009 |
Slides |
Watching the Watcher: The Prevalence of Third-party Web Tracking
|
|
ShmooCon 2009 |
| April 15, 2009 |
Slides |
Get Rich or Die Trying - "Making Money on the Web the Black Hat Way"
|
Jeremiah Grossman
|
Source Conference Boston 2009 |
| April 07, 2009 |
Video |
Why were we so vulnerable to the DNS vulnerability?
|
Dan Kaminsky
|
Chaos Communication Congress 25th (25C3) 2008 |
| March 15, 2009 |
Video |
Grendel-Scan: A new web application scanning tool
|
David Byrne
Eric Duprey
|
DEFCON 16 |
| March 15, 2009 |
Slides |
Grendel-Scan: A new web application scanning tool
|
David Byrne
|
DEFCON 16 |
| March 03, 2009 |
Paper |
Dissecting Web Attacks
|
|
Black Hat DC 2009 |
| February 26, 2009 |
Slides |
Dissecting Web Attacks
|
|
Black Hat DC 2009 |
| January 22, 2009 |
Slides |
Intelligent Web Fuzzing
|
|
Ruxcon 2008 |
| October 18, 2008 |
Paper |
Automated testing of privilege escalation in web applications
|
Ory Segal
|
|
| October 10, 2008 |
Slides |
Security Testing with Selenium
|
Vidar Kongsli
|
|
| July 21, 2008 |
Paper |
Abusing HTML 5 Structured
Client-side Storage
|
Alberto Trivero
|
|
| July 18, 2008 |
Slides |
Website Vulnerabilities Revealed: What everyone knew, but afraid to believe
|
Jeremiah Grossman
|
|
| July 13, 2008 |
Slides |
Web Portals Gateway To Information Or A Hole In Our Perimeter Defenses
|
|
Shmoocon 2008 |
| June 19, 2008 |
Paper |
The Extended HTML Form attack revisited
|
|
|
| June 12, 2008 |
Paper |
Application-Specific Attacks: Leveraging the ActionScript Virtual Machine
|
IBM
|
|
| June 05, 2008 |
Paper |
Bypassing URL Authentication and Authorization with HTTP Verb Tampering
|
Arshan Dabirsiaghi
|
|
| June 02, 2008 |
Paper |
HTML Form Protocol Attack
|
Jochen Topf
|
|
| February 20, 2008 |
Paper |
The Ghost In The Browser Analysis of Web-based Malware
|
Google
|
|
| February 20, 2008 |
Paper |
All Your iFRAMEs Point to Us
|
Google
|
|
| February 09, 2008 |
Paper |
The Future of Web Server Security
|
Yona Hollander
|
|