Hijacking Web 2.0 Sites with SSLstrip--Hands-on Training

DEF CON 17

Presented by: Anonymous Speaker
Date: Saturday August 01, 2009
Time: 15:00 - 15:50
Location: Track 4
Track: Track 4

Many Websites mix secure and insecure content on the same page, like Facebook. This makes it possible to steal all the data entered on such a page easily, using Moxie Marlinspike's new SSLstrip tool. First I will give a brief explanation and demonstration of the technique, and then I will help audience members set up the attack themselves on their own laptops. Detailed instructions and all required software will be provided. Audience members should bring a laptop computer to participate in the hands-on training.

Sam Bowne

<strong>Sam Bowne</strong> has been teaching computer networking and security classes at CCSF since 2000. He has given talks at DEF CON and Toorcon on Ethical Hacking, and taught classes and seminars at many other schools and teaching conferences.<br /><br /> He has a B.S. in Physics from Edinboro University of Pennsylvania and a Ph.D. in Physics from University of Illinois, Urbana-Champaign. His Industry Certifications are: Certified Ethical Hacker, Microsoft: MCP, MCDST, MCTS: Vista; Network+, Security+, Certified Fiber Optic Technician.


KhanFu - Mobile schedules for INFOSEC conferences.
Mobile interface | Alternate Formats