The Fastest Way to Become a Backend Developer Online
Become an AI & ML Engineer with Cal Poly EPaCE — IBM-Certified Training
Overview
AI, Data Science & Cloud Certificates from Google, IBM & Meta — 40% Off
One plan covers every Professional Certificate on Coursera. 40% off Coursera Plus Annual.
Unlock All Certificates
Explore the security implications of Edge Side Includes (ESI) in this 22-minute Black Hat conference talk. Delve into how this legacy technology, still prevalent in popular HTTP surrogates, can be exploited for web-based attacks. Learn about the potential vulnerabilities in caching servers and load balancers that have become crucial to Internet infrastructure. Discover how ESI's design can be leveraged for Server-Side Request Forgery (SSRF) and transparent session hijacking. Gain insights from speaker Louis Dion-Marcil on this unexplored attack vector and its impact on web security.
Syllabus
Edge Side Include Injection: Abusing Caching Servers into SSRF and Transparent Session Hijacking
Taught by
Black Hat