Sessional attacks, what are the new breeds of attacks?

I collect as much information as possible about attacks in http (s) sessions.

There is a lot of information about existing attacks, but I would like to know if new breeds of attacks have appeared either due to security flaws in popular software or technology, or thanks to a new, more reliable security technique.

Do you have any recommendations regarding new methods or tools?

Thank,

+3
source share
1 answer

HTTPS. SSLStrip blackhat 2009 Moxie Marlinspike. .

, . STS, . Firefox STS. Microsoft Apple , , , .

, Dangling Pointers . " " " " , , Pwn2own 2010 IE Windows 7. NX-, ASLR. Dangling Pointers .

+2

Source: https://habr.com/ru/post/1747433/


All Articles