Loading…
Attending this event?
Friday, June 28 • 1:15pm - 2:00pm
Exploiting Client-Side Path Traversal : CSRF is Dead, Long Live CSRF

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

To provide users with a safer browsing experience, the IETF proposal named "Incrementally Better Cookies" set in motion a few important changes to address Cross-Site Request Forgery (CSRF) and other client side issues. Soon after, Chrome and other major browsers implemented the recommended changes and introduced the SameSite attribute. SameSite helps mitigate CSRF, but does that mean CSRF is Dead?




While auditing major web applications, we realized that Client Side Path-Traversal (CSPT) can be actually leveraged to resuscitate CSRF for the joy of all pentesters. Listed in the Top 10 Web Hacking Techniques of 2022, Client Side Path-Traversal has been overlooked for years. While considered by many as a low-impact vulnerability, it can be actually used to force an end user to execute unwanted actions on a web application. 




Once we have introduced the basics of Client Side Path Traversal, we will present sources and sinks for Cross Site Request Forgery. Software engineers will learn how to defend their applications against this new class of vulnerabilities, while security auditors will come back home with a set of tips and tricks to bring CSRF back in their reports. To demonstrate the impact and novelty of our discovery, we will showcase vulnerabilities in major web messaging applications, including Mattermost and Rocket.Chat among others. Finally, we will also release a Burp extension to help the discovery of Client-Side Path-Traversal sources and sinks.


Speakers
avatar for Maxence Schmitt

Maxence Schmitt

Application Security Engineer, Doyensec
Maxence graduated from a French engineering school in Computer Science and Software Engineering and always had an interest in the security field. His professional experience began with managing Identity and Access Management topics in a large French IT consulting company. His skillset... Read More →


Friday June 28, 2024 1:15pm - 2:00pm WEST
Feedback form isn't open yet.

Attendees (2)