DEF CON 32 - Listen to the Whispers: Web Timing Attacks that Actually Work - James Kettle

DEF CON 32 - Listen to the Whispers: Web Timing Attacks that Actually Work - James Kettle

Source: YouTube · DEFCONConference · published Nov 17, 2024 · 42:31

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

Timing attacks can reveal deep, often overlooked vulnerabilities in web applications by measuring response times to detect subtle differences in server behavior. The speaker demonstrates that with proper techniques, timing attacks are not just theoretical but practical, reliable, and applicable across live systems. 0:31

Key Takeaways:
• Timing attacks can detect hidden parameters and headers by analyzing response time differences, even when content remains unchanged 14:00.
• The single packet attack, enhanced with coalescing and DNS header manipulation, overcomes network jitter and enables universal timing attacks on any HTTP/2 target 8:44.
• Timing analysis reveals server-side control flow changes, enabling detection of web application firewall bypasses and server-side request forgery (SSRF) vulnerabilities 23:06.
• These attacks expose internal systems, staging servers, and admin consoles via reverse proxies and header spoofing, with practical exploitation through timing-based reconnaissance 34:14.

Timing attacks are powerful, underutilized tools for uncovering real-world vulnerabilities—often revealing insights that traditional scanning misses. They work best when applied with a clear, focused question and supported by automated tools. 39:18

Sources:

  • 0:31 Introduction to timing attacks and their theoretical vs. real-world divide.
  • 14:00 Use of timing to detect hidden parameters and headers.
  • 8:44 Single packet attack technique overcoming network noise.

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

good morning and welcome to listen to The Whispers first off I'd like to apologize because this talk was not meant to be virtual but my baby daughter arrived 6 weeks early yesterday morning so this wasn't the ideal time to fly to Las Vegas thankfully everyone is well so I do have a little time to talk to you guys about timing attacks timing attacks can evoke some strong emotions they take you into this world where everything is possible in theory and nothing seems to work in reality they leave you asking how can something be this powerful and this useless at the same time how can there be so much research on this topic and so few people applying it dayt day it must be some kind of research at trap and after 10 years of avoiding this trap I decided to step on it and see what happens this st…