Who Is Your Parser And What Does He Do: URL Parsing Gone Wrong

Who Is Your Parser And What Does He Do: URL Parsing Gone Wrong

Description:

Understanding URLs is hard, parsing them is even harder. When we compared different URL parsers, we found that the results varied from one parser to another. That sparked our curiosity and led us to compare URL parsers across different platforms and programming languages. In our presentation, we will discuss numerous exploitation techniques that use URL parsing inconsistencies, as well as some vulnerabilities we've discovered in popular open-source projects used by many applications.

Speakers:

Noam Moshe

Security Researcher, undefined

Patch Logo SegmentPatch Logo SegmentPatch Logo SegmentPatch Logo SegmentPatch Logo SegmentPatch Logo SegmentPatch Logo SegmentPatch Logo SegmentPatch Logo SegmentPatch Logo SegmentPatch Logo SegmentPatch Logo SegmentPatch Logo Segment

Snyk is a developer security platform. Integrating directly into development tools, workflows, and automation pipelines, Snyk makes it easy for teams to find, prioritize, and fix security vulnerabilities in code, dependencies, containers, and infrastructure as code. Supported by industry-leading application and security intelligence, Snyk puts security expertise in any developer’s toolkit.

Start freeBook a live demo

© 2024 Snyk Limited
Registered in England and Wales

logo-devseccon