Because surely no one would…
* write an HTTP server in pure C
* …without modern libraries…
* and then run it as root
* in production, on a few million machines
Oh wait.
Well, anyway - What’s the Venn diagram of developers who truly understand:
* C and pointers
* web application security
* the intricacies of HTTP parsing
* SOP, CORS & CSP
* CSRF & SSRF
Let’s try to answer this by doing fun things like reading the spec and staring at the source code with a mean-looking face until it spills all its secrets.
❗️Anyone is invited who thinks that “reading the spec” is a fun way to spend an evening.
🙈🖨 Infosec Wednesday — string parsing is trivial edition 🖨
🫠 19:00 (till ~22:00) Wednesday, March 4
🍪 F0RTHSP4CE, Ana Kalandadze 5
🧠 Language: Markdown only, sorry.md!
😈 Entrance: donation towards f0
🤔 Hosts: @zrthstr @Crimpflick
Fun activities like:
* reading the spec
* src code analysis
* attack surface modeling
* preparing *nix systems & daemons for debugging
* reading the src until you wanna give up and cry
* building protocol-level fuzzers
RSVP with a reaction if you’re in (🔥 yes / 🤔 maybe).
Post #512
1.15K
- 🤔 7
- 🔥 6
- 👏 6