toctou
toctou ha conseguito una laurea magistrale in Ingegneria della Sicurezza informatica presso l'Università di Verona. Ha iniziato la sua carriera come analista di Cyber Security, cambiando poi bruscamente rotta diventando Senior Oracle Database Administrator con oltre dieci anni di esperienza nel settore IT. Da poco è poi riuscito a tornare alle radici virando di nuovo carriera e diventando Penetration Tester. È certificato come OffSec Certified Professional (OSCP) e OffSec Experienced Penetration Tester (OSEP). Come appassionato di cybersecurity è sempre desideroso di studiare e ampliare le conoscenze e le competenze pratiche in materia di sicurezza informatica nel tempo libero e, come attività secondaria, attualmente crea macchine vulnerabili per OffSec come autore freelance.
Session
Standard OIDC bearer tokens are deceptively simple and highly attractive to developers, but they hide a structurally weak security posture: anyone who holds them can spend them. Following up on our previous deep dive @MOCA24 into securing OIDC code exchanges, this presentation is a hands-on, exploit-driven exploration of token-usage security.
We will begin by demonstrating how easily standard bearer tokens are stolen and replayed remotely from an attacker's terminal. We will then look "beyond the basics" to live-demo a hardened implementation of RFC 9449 (DPoP) using a Keycloak identity provider and an Express.js resource server.