Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

Compression Bombs Strike Back

OWASP Foundation via YouTube

Overview

AI, Data Science & Cloud Certificates from Google, IBM & Meta — 50% Off
One plan covers every Professional Certificate on Coursera. 50% off Coursera Plus Annual for 10 days only — price increases June 17.
Unlock All Certificates
Explore the security risks associated with data compression in HTTP protocols through this 39-minute conference talk from AppSecEU 2016 in Rome. Delve into the concept of compression bombs, their impact on implementations, and potential vulnerabilities in server systems. Learn about XML bombs, protocol specifications, and HTTP compression attacks. Examine experimental setups, HTTP response compression, and common pitfalls such as compression before authentication and during input validation. Gain insights into the challenges of communication between units and draw valuable conclusions for enhancing web application security.

Syllabus

Introduction
What is Slide
Data Compression
What is Compression
Compression in HTTP
Compression HTTP
Data Compression Risks
XML Bomb
Protocol Specification
Impact on implementations
HTTP compression attack
Vulnerabilities
Attacking servers
Experiment setup
HTTP response compression
Pitfalls
Compression before authentication
Compression during input validation
Communication between units
Conclusion

Taught by

OWASP Foundation

Reviews

Start your review of Compression Bombs Strike Back

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.