
DEF CON 33 - Paywall Optional: Stream for Free w/ New Technique, RRE - Farzan Karim
Source: YouTube · DEFCONConference · published Oct 10, 2025 · 20:19
Farzan Karemi introduces Recursive Request Exploits (RRE), a new technique for bypassing authentication systems and paywalls by tracing web requests in reverse to find weak points in API chains 0:57-1:16.
Key Takeaways:
• RRE works by identifying where sensitive values are first introduced in web applications, where trust assumptions are strong but authentication is weakest 5:26-5:55
• The technique enabled the speaker to bypass paywalls on sports streaming services and access all their content for free by tracing API chains back to unauthenticated entry points 1:21-1:28
• Using automation with entropy checks, the process that would take days manually can be completed in seconds, scaling the exploitation across entire content libraries 14:55-15:25
• The discovery of "always on" live streams presents significant privacy concerns as cameras can be accessed anytime with the right API parameters 16:08-16:28
RRE represents a powerful new approach to identifying authentication flaws in complex web applications with significant implications for digital rights management and corporate security 17:46-17:52.
Sources:
- 0:57-1:16 Introduction to RRE technique
- 5:26-5:55 Explanation of the ABSAC principle
- 1:21-1:28 Examples of RRE exploitation
- 14:55-15:25 Demonstration of automated RRE tool
- 16:08-16:28 Privacy implications of live streams
- 17:46-17:52(https://www.youtube.com/watch?v=U
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Penetration Testing. Commonly maps to: Security Assessment and Testing, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
Hey everyone, can you hear me? >> All right, we're good to go. Welcome everyone to Defcon. >> Yeah. Um, yeah. So, I'm super excited to be back here at Defcon speaking again. Um, I'm Farzan Karemi. I'm an offensive security researcher. Uh, and, uh, this is my talk, my session, Paywall Optional, stream for free with a new technique, recursive request exploits. Um, little bit of cross talk that I'm hearing. Hopefully, you're not hearing that too bad. Um, so anyways, uh, uh, this is my session. Uh, why did I choose a title focused on bypassing payw walls, right? Uh, so the important thing here is you really have to know your audience here at Defcon. And when you say something like steam stream for free, you really rally all the cheap skates into one room. Yeah. And I mean that as a compliment …