44CON Announce logo

44CON Announce

Subscribe
Archives
November 26, 2020

[44Con Announce] 44CON December Live Online Training

|IF:MC_PREVIEW_TEXT|

[if !gte mso 9]>|MC_PREVIEW_TEXT|

img
Try viewing this email in your browser
end header bar header left
44CON December Training
We hope you enjoyed our first free introduction webinar if you attended yesterday.
Check out the four live online courses we have lined up for you in December, one with Dawid Czagan and three ones with 7aSecurity.
Bypassing CSP via ajax.googleapis.com

Content Security Policy (CSP) is the number one defensive technology in modern web applications. Many developers add ajax.googleapis.com to CSP definitions, because they use libraries from this very popular CDN in their web applications. The problem is that it completely bypasses the CSP and obviously you don’t want that to happen.

In a free video Dawid Czagan (44CON Instructor) will show you step-by-step how this attack works and tell you how to prevent this attack from happening.

Watch this free video and feel the taste of Dawid Czagan’s Live Online Training ”Black Belt Pentesting / Bug Hunting Millionaire: Mastering Web Attacks with Full-Stack Exploitation” (44CON Live Online Training; 15-16 December 2020; https://44con.com/product/black-belt-pentesting-december-2020/)

Watch the video →
We still have two more free webinars to come.

7aSecurity will be running two more free 1 hr webinars to introduce you to the courses they will run in December:

  • Hacking Modern Web apps with RCE and Prototype Pollution on Monday 23rd November 2020 at 5 p.m. GMT - Get your free ticket here.
  • Hacking Modern Desktop apps with XSS and RCE on Wednesday 25th November 2020 at 5 p.m. GMT - Get your free ticket here.
Get your free tickets →
Check our live online training courses in December
  • Hacking Android, iOS and IoT apps by Example – 1-4 Dec 2020 (4 1/2 days)
  • Black Belt Pentesting / Bug Hunting Millionaire: Mastering Web Attacks with Full-Stack Exploitation – 15-16 Dec 2020
  • Hacking Modern Desktop apps: Master the Future of Attack Vectors: December 2020 – 15-18 Dec 2020 (4 1/2 days)
  • Hacking Modern Web apps: Master the Future of Attack Vectors: December 2020 – 15-18 Dec 2020 (4 1/2 days)
Read more →
end header left 1/2 right 1 end 1/2 right 1 1/2 left 1 end 1/2 left 1 cta end cta headline end headline 1/1 panel end 1/1 panel 2/2 content end 2/2 content 3/3 content end 3/3 content 2/2 panel end 2/2 panel 3/3 panel end 3/3 panel profile end profile contact end contact 1/2 left 2 end 1/2 left 2 1/2 right 2 end 1/2 right 2 header right end header right content right end content right content left end content left quote end quote 1/3 left end 1/3 left 1/3 right end 1/3 right 1/1 content end 1/1 content footer

end footer

img
img @44CON
About 44CON
Since 2011 we've been breaking things, highlighting flaws and presenting the latest international research in London, UK. We have gone online for the time being.
If you’d prefer not to receive updates, you can unsubscribe here.
Don't miss what's next. Subscribe to 44CON Announce:
Website Bluesky X LinkedIn Facebook
Powered by Buttondown, the easiest way to start and grow your newsletter.