Hacking with WebSockets

Presented at ToorCon San Diego 14 (2012), Oct. 20, 2012, 4 p.m. (50 minutes)

The talk includes couple of demos of WebSockets usage in civilian and hacking applications, and goes into details of protocol dissection and performance benefits that it may bring. Analysis of  current WebSockets usage is performed and data showing not-so-widespread adoption is presented. Security aspects of WebSockets  are discussed including few shortcomings of current implementations and browser related issues. Also, on the spotlight are the complications that may arise from WebSockets mixed usage with HTTP, as well as the problems that network protection infrastructures will face because of the masking of WebSockets data. It closes with recommendations for deploying WebSockets securely, applying security principles to web app design.


Presenters:

  • Vaagn Toukharian
    Senior software engineer for Qualys's Web Application Scanner. Was involved with security industry since 1999. Experience includes work on Certification Authority systems, encryption devices, large CAD systems, Web scanners. Outside of work interests include Photography, and Ironman Triathlons.

Similar Presentations: