It’s worth a shot.
https://youtu.be/7W5au-IJUEc
Its worth a shot. https://youtu.be/7W5au-IJUEc Approach 1. What - - PowerPoint PPT Presentation
Its worth a shot. https://youtu.be/7W5au-IJUEc Approach 1. What created the vulnerability. 2. How the vulnerability is exploited. 3. How to protect yourself. Web 2.0 What could possibly go wrong?! Servers send HTML and JS to clients
https://youtu.be/7W5au-IJUEc
Server HTML, CSS, JS Bingo
salt+hash Hash function password random salt hash
salt+hash Hash function password match? salt hash hash to check Are hashed passwords uncrackable? No!
Server Bingo HTTP POST username, password salt+hash Bongo Thanks!
Server Bingo HTTPS POST username, password token
Server Bingo token OK Bongo fake token nope
www.bongo.com
Check this out! www.bank.com/profile?name=<script>...
Server Bingo transfer <cookie> OK
www.bongo.com
GET www.bongo.com malicious content