Parser Differentials: Finding Security Vulnerabilities in JSON Parsing
BSides Budapest IT Security Conference via YouTube
Finance Certifications Goldman Sachs & Amazon Teams Trust
The Fastest Way to Become a Backend Developer Online
Overview
Google, IBM & Meta Certificates — All 10,000+ Courses at 40% Off
One annual plan covers every course and certificate on Coursera. 40% off for a limited time.
Get Full Access
Explore a 43-minute conference talk from BSides Budapest IT Security Conference that delves into the security implications of parser differentials - instances where multiple parsers interpret the same structured message differently. Learn how these inconsistencies can create security vulnerabilities, even in seemingly simple formats like JSON. Discover the challenges of identifying parser differentials through fuzzing techniques, including methods for parallel parser testing and automated result classification. Gain practical insights through demonstrations of JSON parser differentials and understand why parsing structured messages isn't as straightforward as it might appear. Master the technical approaches to discovering these hidden threats and their potential impact on system security.
Syllabus
BSidesBUD2023: Parser Differentials
Taught by
BSides Budapest IT Security Conference