#NahamCon2024
Vložit
- čas přidán 24. 05. 2024
- Modern WAF Bypass Techniques on Large Attack Surfaces 👇
Shubham Shah is a security researcher and entrepreneur, known for co-founding Assetnote - a leading attack surface management platform. He's ranked as the #1 bug bounty hunter in Australia for three consecutive years and #27 in the world on HackerOne. Shubham specializes in discovering complex vulnerabilities in enterprise software and engineering security automation.
nowafpls:
github.com/assetnote/nowafpls
JOIN DISCORD:
discord.gg/NahamSec
💬 Social Media
- / nahamsec
- / nahamsec
- twitch.com/nahamsec
- / nahamsec1
Shubs is like, "Have you ever heard of the internet? Yeah, I own it."
Wow! This was amazing! Thank you, sir. Greatly appreciated.
Thanks, Shubs for showing some cool techniques for WAF bypasses. I guess the community had long waited for this! Even though some WAF bypasses were not new, but many people knew this for sure.
Great talk, glad to see it here too
Thank you Shah , Good topic
Great presentation and really appreciated the fun and engaging delivery. Big thanks again for putting on NahamCon2024 ❤❤
ANYTIME I see Shubs in the thumbnail, I'm clicking on it! Thanx for the tips!! 💪
Great talk thanks for NAHAMCON Ben :)
Wow keep it up , present 😊
Brilliant!!!
Thanks
Nice!!
Super infromative
Nice tips
wow
Nice talk
Can these tools be ran from a laptop this is the first video I've seen on them thanks again Ben you still da man Bro :)
Shadow clone is like axiom finally
With the shared certificates trick(cross-tenant attacks). You will have to know the origin IP of the target right?
Will/Have the slides been released?
Amazing Doc.
I certainly doubt nowafpls working, but happy to be wrong.
And i highly doubt you know anything about web hacking and who is this guy lmao
Ok. This only applies to cloud WAF.
Taking the piss with the advertisements
?
@@NahamSec Love the video but 8 adverts really cheesed me off
Use of shared certificates is why I disliked akamai, they do not support bring your own certs....terrible!