• Email
  • Like
  • Save
  • Private Content
  • Embed
 

Http Parameter Pollution, a new category of web attacks

by on May 19, 2009

  • 32,559 views

On May 14th @ OWASP Appsec Poland 2009, Stefano Di Paola (Minded Security) and Luca Carettoni presented a new attack category called...

On May 14th @ OWASP Appsec Poland 2009, Stefano Di Paola (Minded Security) and Luca Carettoni presented a new attack category called
Http Parameter Pollution (HPP).

HPP attacks can be defined as the possibility to override or add HTTP GET/POST parameters by injecting query string
delimiters.
It affects a building block of all web technologies thus server-side and client-side attacks exist.
Exploiting HPP vulnerabilities, it may be possible to:
* Override existing hardcoded HTTP parameters.
* Modify the application behaviors.
* Access and, potentially exploit, uncontrollable variables.
* Bypass input validation checkpoints and WAFs rules.

Accessibility

Categories

Upload Details

Uploaded via SlideShare as Adobe PDF

Usage Rights

© All Rights Reserved

Flagged as inappropriate Flag as inappropriate
Flag as inappropriate

Select your reason for flagging this presentation as inappropriate. If needed, use the feedback form to let us know more details.

Cancel

66 Embeds 12,728

http://www.securitytube.net 3264
http://www.rafayhackingarticles.net 3092
http://prohackersden.blogspot.com 2448
http://feeds.feedburner.com 905
http://www.elladodelmal.com 856
http://www.protezioneaccount.com 422
http://bharath-marrivada.blogspot.com 400
http://bharath-marrivada.blogspot.in 352
http://www.nsai.it 284
http://securitytube.net 178
http://blog.segu-info.com.ar 85
http://prajwal-tuladhar.net.np 81
http://feeds2.feedburner.com 57
http://www.slideshare.net 43
http://bharath-marrivada.blogspot.co.uk 42
http://translate.googleusercontent.com 40
http://static.slidesharecdn.com 30
http://bharath-marrivada.blogspot.ca 17
http://blog.neodyme.net 13
http://www.bonweb.fr 12
http://webcache.googleusercontent.com 8
http://bharath-marrivada.blogspot.com.au 7
http://www.neodyme.net 6
http://bharath-marrivada.blogspot.de 5
http://toysone.blogspot.com 5
http://bharath-marrivada.blogspot.sg 4
http://www.plurk.com 4
http://bharath-marrivada.blogspot.com.br 4
http://bharath-marrivada.blogspot.tw 4
http://rsscorner.com 4
http://www.prohackersden.blogspot.com 3
http://securitytube-hrd.appspot.com 3
http://bharath-marrivada.blogspot.fi 3
http://bharath-marrivada.blogspot.com.ar 3
http://bharath-marrivada.blogspot.co.nz 3
http://bharath-marrivada.blogspot.nl 3
http://37com.mail.everyone.net 2
http://www.bharath-marrivada.blogspot.in 2
http://bharath-marrivada.blogspot.cz 2
http://bharath-marrivada.blogspot.fr 2
http://bharath-marrivada.blogspot.ro 2
http://2.securitytube-hrd.appspot.com 2
http://bharath-marrivada.blogspot.kr 2
http://twitter.com 2
http://www.printwhatyoulike.com 1
http://www.imhotep.biz 1
http://bharath-marrivada.blogspot.hk 1
http://zapp5.staticworld.net 1
http://images.watoday.com.au 1
http://131.253.14.66 1
http://www.google.es 1

More...

Statistics

Likes
10
Downloads
314
Comments
2
Embed Views
12,728
Views on SlideShare
19,831
Total Views
32,559

12 of 2 previous next

  • zchalex Zch Alex at Trend Micro Http Parameter Pollution, a new category of web attacks 1 year ago
    Are you sure you want to
  • mnot Mark Nottingham, person at mnot.net HTTP doesn't define the syntax of query strings; the format you're talking about is defined by HTML. So, it'd be more accurate to call this something else. 2 years ago
    Are you sure you want to
Post Comment
Edit your comment

Http Parameter Pollution, a new category of web attacks Http Parameter Pollution, a new category of web attacks Presentation Transcript