About this talk
This talk examines the potential for attackers to exfiltrate sensitive data through next-generation firewalls via a zero-day covert channel within the TLS Client Hello handshake, as presented by Rakesh Seal from Keysight Technologies. The speaker reveals how altering the order of TLS extensions and cipher suites allows data to be encoded and transmitted invisibly, emulating the JA3 fingerprint-evasion techniques of browsers like Chrome and Firefox. The session covers the effectiveness of this technique against major firewalls in laboratory tests, as well as insights gained from responsible disclosures to security organizations and vendors regarding mitigations available to security teams against such protocol-layer covert channels.
More from this event
See all 28 talks →
Ai, Deception And Deepfakes When Trust Becomes The Primary Attack Surface
36:15
Cloud Resilience Simplified Less Data, Stronger Security
33:14
Demystifying Driver Research A Systematic Approach For Vulnerability Hunting
25:24
Dpdpa In Action Designing A 72 Hour Breach Response That Actually Works
22:56