Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

Diving into Windows HTTP - Unveiling Hidden Preauth Vulnerabilities in Windows HTTP Services

Black Hat via YouTube

Overview

Coursera Flash Sale
40% Off Coursera Plus for 3 Months!
Grab it
Explore the security landscape of Windows HTTP services through this 36-minute pre-recorded conference talk that reveals critical vulnerabilities across the Windows ecosystem. Delve into comprehensive research conducted by security experts from Cyber Kunlun Lab and Huazhong University of Science and Technology, who analyzed the internal mechanisms of Windows HTTP components and uncovered over 100 critical pre-authentication vulnerabilities. Learn about the different architectures of Windows HTTP services including IIS, ADFS, ADCS, Hyper-V, Kerberos, WSUS, Windows Storage, SSDP, UPnP, WinRM, RDP, BranchCache, and MSMQ, and understand how these services support crucial functions within the Windows operating system. Discover novel vulnerability patterns that include both classic memory corruption bugs and logical vulnerabilities caused by incorrect usage of Windows HTTP APIs by developers. Examine specific vulnerability cases covering pre-auth remote code execution (RCE), information leakage, and denial-of-service (DoS) attacks that require no credentials, additional configurations, or user interaction, making any Windows system running these services potentially vulnerable. Gain insights into previously undisclosed attack vectors and understand the comprehensive security threats within Windows HTTP services through detailed case studies and vulnerability pattern analysis presented by leading security researchers in the field.

Syllabus

Diving into Windows HTTP: Unveiling Hidden Preauth Vulnerabilities in Windows HTTP Services

Taught by

Black Hat

Reviews

Start your review of Diving into Windows HTTP - Unveiling Hidden Preauth Vulnerabilities in Windows HTTP Services

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.