#NahamCon2024

Sdílet
Vložit
  • čas přidán 24. 05. 2024
  • Modern WAF Bypass Techniques on Large Attack Surfaces 👇
    Shubham Shah is a security researcher and entrepreneur, known for co-founding Assetnote - a leading attack surface management platform. He's ranked as the #1 bug bounty hunter in Australia for three consecutive years and #27 in the world on HackerOne. Shubham specializes in discovering complex vulnerabilities in enterprise software and engineering security automation.
    nowafpls:
    github.com/assetnote/nowafpls
    JOIN DISCORD:
    discord.gg/NahamSec
    💬 Social Media
    - / nahamsec
    - / nahamsec
    - twitch.com/nahamsec
    - / nahamsec1

Komentáře • 26

  • @detecht
    @detecht Před měsícem +6

    Shubs is like, "Have you ever heard of the internet? Yeah, I own it."
    Wow! This was amazing! Thank you, sir. Greatly appreciated.

  • @Ott3rly
    @Ott3rly Před měsícem +1

    Thanks, Shubs for showing some cool techniques for WAF bypasses. I guess the community had long waited for this! Even though some WAF bypasses were not new, but many people knew this for sure.

  • @Dkdiebebdjdb
    @Dkdiebebdjdb Před měsícem

    Great talk, glad to see it here too

  • @golfreeze
    @golfreeze Před měsícem

    Thank you Shah , Good topic

  • @HopliteSecurity
    @HopliteSecurity Před měsícem

    Great presentation and really appreciated the fun and engaging delivery. Big thanks again for putting on NahamCon2024 ❤❤

  • @Blu3ther
    @Blu3ther Před měsícem

    ANYTIME I see Shubs in the thumbnail, I'm clicking on it! Thanx for the tips!! 💪

  • @MFoster392
    @MFoster392 Před měsícem

    Great talk thanks for NAHAMCON Ben :)

  • @rctech1237
    @rctech1237 Před měsícem +1

    Wow keep it up , present 😊

  • @thatonesecguy
    @thatonesecguy Před 29 dny

    Brilliant!!!

  • @d1_v_1ne
    @d1_v_1ne Před měsícem

    Thanks

  • @bokfpv
    @bokfpv Před měsícem

    Nice!!

  • @WebWonders1
    @WebWonders1 Před měsícem

    Super infromative

  • @breakoutgaffe4027
    @breakoutgaffe4027 Před měsícem

    Nice tips

  • @ranoshlover
    @ranoshlover Před měsícem

    wow

  • @romeokoati5385
    @romeokoati5385 Před měsícem

    Nice talk

  • @MFoster392
    @MFoster392 Před měsícem

    Can these tools be ran from a laptop this is the first video I've seen on them thanks again Ben you still da man Bro :)

  • @trustedsecurity6039
    @trustedsecurity6039 Před 16 dny

    Shadow clone is like axiom finally

  • @Mersal-tq9lm
    @Mersal-tq9lm Před 19 dny

    With the shared certificates trick(cross-tenant attacks). You will have to know the origin IP of the target right?

  • @InfoSecIntel
    @InfoSecIntel Před měsícem

    Will/Have the slides been released?

  • @parthshukla1216
    @parthshukla1216 Před 24 dny

    Amazing Doc.
    I certainly doubt nowafpls working, but happy to be wrong.

    • @trustedsecurity6039
      @trustedsecurity6039 Před 16 dny +1

      And i highly doubt you know anything about web hacking and who is this guy lmao

  • @jesperwall839
    @jesperwall839 Před 28 dny +1

    Ok. This only applies to cloud WAF.

  • @TheRustyCodger
    @TheRustyCodger Před 15 dny

    Taking the piss with the advertisements

  • @okonkwochukwudalu9340
    @okonkwochukwudalu9340 Před 28 dny

    Use of shared certificates is why I disliked akamai, they do not support bring your own certs....terrible!