#NahamCon2024

Поділитися
Вставка
  • Опубліковано 26 вер 2024
  • Modern WAF Bypass Techniques on Large Attack Surfaces 👇
    Shubham Shah is a security researcher and entrepreneur, known for co-founding Assetnote - a leading attack surface management platform. He's ranked as the #1 bug bounty hunter in Australia for three consecutive years and #27 in the world on HackerOne. Shubham specializes in discovering complex vulnerabilities in enterprise software and engineering security automation.
    nowafpls:
    github.com/ass...
    JOIN DISCORD:
    discord.gg/NahamSec
    💬 Social Media
    - / nahamsec
    - / nahamsec
    - twitch.com/nah...
    - / nahamsec1

КОМЕНТАРІ • 26

  • @detecht
    @detecht 4 місяці тому +8

    Shubs is like, "Have you ever heard of the internet? Yeah, I own it."
    Wow! This was amazing! Thank you, sir. Greatly appreciated.

  • @Ott3rly
    @Ott3rly 4 місяці тому +2

    Thanks, Shubs for showing some cool techniques for WAF bypasses. I guess the community had long waited for this! Even though some WAF bypasses were not new, but many people knew this for sure.

  • @HopliteSecurity
    @HopliteSecurity 4 місяці тому

    Great presentation and really appreciated the fun and engaging delivery. Big thanks again for putting on NahamCon2024 ❤❤

  • @Blu3ther
    @Blu3ther 4 місяці тому

    ANYTIME I see Shubs in the thumbnail, I'm clicking on it! Thanx for the tips!! 💪

  • @MFoster392
    @MFoster392 4 місяці тому

    Great talk thanks for NAHAMCON Ben :)

  • @Dkdiebebdjdb
    @Dkdiebebdjdb 4 місяці тому

    Great talk, glad to see it here too

  • @golfreeze
    @golfreeze 4 місяці тому

    Thank you Shah , Good topic

  • @rctech1237
    @rctech1237 4 місяці тому +1

    Wow keep it up , present 😊

  • @MFoster392
    @MFoster392 4 місяці тому

    Can these tools be ran from a laptop this is the first video I've seen on them thanks again Ben you still da man Bro :)

  • @thatonesecguy
    @thatonesecguy 4 місяці тому

    Brilliant!!!

  • @shareb1t
    @shareb1t Місяць тому

    Caido made way into these videos lmao , i can see some crime websites as flare too

  • @WebWonders1
    @WebWonders1 4 місяці тому

    Super infromative

  • @d1_v_1ne
    @d1_v_1ne 4 місяці тому

    Thanks

  • @breakoutgaffe4027
    @breakoutgaffe4027 4 місяці тому

    Nice tips

  • @bokfpv
    @bokfpv 4 місяці тому

    Nice!!

  • @romeokoati5385
    @romeokoati5385 4 місяці тому

    Nice talk

  • @ranoshlover
    @ranoshlover 4 місяці тому

    wow

  • @trustedsecurity6039
    @trustedsecurity6039 3 місяці тому

    Shadow clone is like axiom finally

  • @parthshukla1216
    @parthshukla1216 3 місяці тому

    Amazing Doc.
    I certainly doubt nowafpls working, but happy to be wrong.

    • @trustedsecurity6039
      @trustedsecurity6039 3 місяці тому +1

      And i highly doubt you know anything about web hacking and who is this guy lmao

    • @parthshukla1216
      @parthshukla1216 2 місяці тому +1

      @@trustedsecurity6039 This is not PCI compliance relax. Just try the tool and then tell. Oh wait! but you wont get blocked because pretty sure your attacks are not that powerful. LMAO

    • @trustedsecurity6039
      @trustedsecurity6039 2 місяці тому

      @@parthshukla1216 just talking about PCI compliance when it comes to bypass/hacking show your dont have the basics of web pentesting LMAO I do web pentest everyday... And this guy do it since you wasnt even born... And to finish it is a bypass he use since years and we use it for years ;) it is like when EDR didnt scan large files too... Not PCI compliance LMAO

  • @InfoSecIntel
    @InfoSecIntel 4 місяці тому

    Will/Have the slides been released?

  • @Mersal-tq9lm
    @Mersal-tq9lm 3 місяці тому

    With the shared certificates trick(cross-tenant attacks). You will have to know the origin IP of the target right?

  • @jesperwall839
    @jesperwall839 3 місяці тому +1

    Ok. This only applies to cloud WAF.

  • @okonkwochukwudalu9340
    @okonkwochukwudalu9340 3 місяці тому

    Use of shared certificates is why I disliked akamai, they do not support bring your own certs....terrible!