Revenge of the Geeks: Hacking Fantasy Sports Sites - Dan Kuykendall
1,246 views · Published 28 November 2013 · 45:50 · Indexed 30 September 2026
Channel: OWASP Foundation · 2013 · Science & Technology
Revenge of the Geeks: Hacking Fantasy Sports Sites - Dan Kuykendall In this talk, I'll show how all my IT security geek friends in the OWASP community can win the Super Bowl! I'll walk through the anatomy of a hack against popular Fantasy Football and Baseball mobile applications showing every "sneak play" required to control the application. The tools and techniques used in this hack can be applied against any mobile application. These applications leverage rich new formats like JSON and REST to deliver a rich user experience, and are not surprisingly exposing the same familiar vulnerabilities like SQL and command injection, yet are not being effectively tested. In this particular application, mistakes with the application's session management enable me to break down the nested communication formats and finally inject targeted payloads to manipulate both team lineups, to make sure my players were on top and to cause my opponents to lose. I also found that I could post false comments on the message board from the victims account. After we walk through the sack, I mean hack, we'll abstract these techniques, tie them directly to OWASP best practices, and apply them to other mobile applications so participants will walk away with specific tools and techniques to better understand mobile back-end hacking. Are you ready for some football? This presentation will: --Provide overview and details about each of the various formats (JSON, REST, SOAP, GWTk, and AMF) in popular use today --Provide clear examples of basic mobile app insecurityRevenge of the Geeks: Hacking Fantasy Sports Sites In this talk, I'll show how all my IT security geek friends in the OWASP community can win the Super Bowl! I'll walk through the anatomy of a hack against popular Fantasy Football and Baseball mobile applications showing every "sneak play" required to control the application. The tools and techniques used in this hack can be applied against any mobile application. These applications leverage rich new formats like JSON and REST to deliver a rich user experience, and are not surprisingly exposing the same familiar vulnerabilities like SQL and command injection, yet are not being effectively tested. In this particular application, mistakes with the application's session management enable me to break down the nested communication formats and finally inject targeted payloads to manipulate both team lineups, to make sure my players were on top and to cause my opponents to lose. I also found that I could post false comments on the message board from the victims account. After we walk through the sack, I mean hack, we'll abstract these techniques, tie them directly to OWASP best practices, and apply them to other mobile applications so participants will walk away with specific tools and techniques to better understand mobile back-end hacking. Are you ready for some football? This presentation will: --Provide overview and details about each of the various formats (JSON, REST, SOAP, GWTk, and AMF) in popular use today --Provide clear examples of basic mobile app insecurity --Demonstrate how to setup an environment to start watching mobile traffic, including how to leverage Wifi Pineapple hardware to set up a local access point --Demonstrate how to inject malicious characters into these services to find vulnerabilities --Discuss what tools are available to automate this process and make it a little easier --Show examples of real vulnerabilities in mobile apps in use today Attendees will be given a whitepaper with the details of the complete setup demonstrated in the talk. Speaker Dan Kuykendall co-CEO and CTO, NT OBJECTives Biography: | | Dan Kuykendall manages NT OBJECTives' software development and handles NTO's relationships with several partner companies. He has an extensive background in web application development and security. As part of the founding team, Dan has been involved in the methodologies and design of NTO's flagship product since its inception. - Managed by the official OWASP Media Project https://www.owasp.org/index.php/OWASP_Media_Project
More from this channel
-
35:56
HTML5 JS Security - maty siman
-
46:05
Next Generation Red Teaming - Robert Wood
-
17:39
detecting and defending against state actor surveillance: robert r
-
50:12
OWASP Global Webinar - OWASP HIVE Project - Welcome to the Grid
-
50:42
OWASP Global Webinar - Initiatives OWASP Projects
-
2:45:16
OWASP Board June 27, 2014 - part 2 (With Quorum)
-
42:16
Alvaro Muoz - Automatic Detection of Inadequate Authorization Checks in Web Applications
-
40:10
Tin Zaw Scott Matsumoto - Threat Modeling A Brief History and the Unified Approach at Intuit