Top 10 winner
Million Browser Botnet
Grossman and Johansen show ad networks will run arbitrary attacker JavaScript, so a $0.15 CPM buy rents a million browsers with no exploit or malware. The rented browsers do CSRF, login detection, deanonymisation, intranet scanning, hash cracking and application-level DDoS; a connection-limit bypass using ftp:// image URLs lifts 6 requests per host to about 300.
Record
- Researcher
- Jeremiah Grossman and Matt Johansen
- Published by
- WhiteHat Security
- Format
- Slides
- Topic
- Browser
In the archive
Related sources
- Black Hat 2013 - Million Browser Botnet Recording
- Black Hat USA 2013
- Black Hat 2013 - Million Browser Botnet
- Black Hat USA 2013 - Million Browser Botnet
- Million Browser Botnet - Jeremiah Grossman Matt Johanssen
Tags
This page is the archive's own catalogue record. The research is the work of Jeremiah Grossman and Matt Johansen, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .