Exploiting IPC With New Desynchronization Primitives
Hack In The Box Security Conference via YouTube
Master Production-Ready Machine Learning, Step by Step
Earn Your CS Degree, Tuition-Free, 100% Online!
Overview
Google, IBM & Meta Certificates – 40% Off
One Coursera Plus subscription covers most Professional Certificates on Coursera.
Unlock All Certificates
This talk demonstrates HTTP desynchronization and memory corruption exploits against SAP’s HTTP server, including credential hijacking, cache poisoning, and remote code execution. It also reviews defenses and presents a detection tool for CVE-2022-22536.
Syllabus
#HITB2023AMS D2T2 - Exploiting IPC With New Desynchronization Primitives - Martin Doyhenard
Taught by
Hack In The Box Security Conference