Attacking Web Proxies in the Modern Era

Presented at NolaCon 2015, June 12, 2015, 2 p.m. (Unknown duration)

Web proxies play a very crucial role for internet users today, from using it for anonymous surfing, bypassing restricted websites and whole lot of other user cases. However, the generic architecture in which web proxies are built over the years, pose several risks to the modern websites being proxied and used by the anonymous surfer. This talk is about subverting the security restrictions of the browser and websites, when an user is using any web proxy. We talk about how the browser's same origin policy is rendered completely ineffective, how cookies are completely owned, how a website's security mitigations are made futile. We also present a secure web proxy architecture that most of the modern day web proxies and web proxy frameworks should follow.


Presenters:

  • Ahamed Nafeez
    Ahamed Nafeez is a security engineer with interest in browser and network security. In the past, he has been a speaker at Nullcon, Black Hat, and Hack-In-The-Box. He loves working on solutions to build defensive softwares and ways to detect attacks.

Links:

Similar Presentations: