Hunting Security Bugs In Web Apps - Suleman Malik

Hunting Security Bugs In Web Apps - Suleman Malik

This talk was presented at OWASP London Chapter Meeting on 28-Sep-2017 at John Lewis Partnership HQ. The slides can be downloaded here: https://www.owasp.org/images/c/ce/OWA... There are so many web applications that work in the background but it can be difficult to know about them. In this talk I’m going to show you some bug hunting techniques and how I exploited vulnerabilities in some major websites. I will cover some topics, which includes bypassing Content Security Policy (CSP), API endpoint vulnerability, PostMessage vulnerability, CSRF, XSS, Session/Authentication flaws and exploiting some other OWASP Top 10 vulnerabilities. Suleman Malik is an independent security researcher and author specialising in web application security, IOS and Android application security. He has reported many security issues under the industry practice of coordinated disclosure. Suleman is listed in more than 50 Halls of Fame including Google, Microsoft, Intel, Sony, LinkedIN, Blackberry, Apple, Oracle, Huawei, US Department of Defense and so on. He has been featured in top cyber security magazines including hakin9 & Pentest magazine and also has been declared as one of top ten highest paid security researchers in the world. HackerOne CEO also has acknowledged his work and invited him to visit the United States of America. Donald Freese, the director of FBi's cyber crime unit (NCIJTF) has also endorsed his skills. Suleman is currently a full time student working toward his degree in computer forensics and security