RuCTF is annual open intercollegiate competition and conference on information security.
This is old channel, please follow @RuCTF
Post #425
120

Right after Denis, Ilja will give a speech "From memory leak to RCE: how dangerous can be processing of mediafiles".
The speech is devoted to the analysis of attacks on web apps, which process media files. You will learn what unsafe processing of images, video/audio files, documents and archives may lead to, and also you will see the examples of exploitation of vulnerabilities.
You will see XXE-attacks in XML-documents, why ImageMagick and ffmpeg are security holes, attacks through MetaData of media files, tools for exploitation of vulnerabilities in processing media files.
The speech is devoted to the analysis of attacks on web apps, which process media files. You will learn what unsafe processing of images, video/audio files, documents and archives may lead to, and also you will see the examples of exploitation of vulnerabilities.
You will see XXE-attacks in XML-documents, why ImageMagick and ffmpeg are security holes, attacks through MetaData of media files, tools for exploitation of vulnerabilities in processing media files.






