XMPP Connectivity & Security

moparisthebest

July 13, 2023

Video of talk at FOSSY

Discovering XMPP

Connectivity

Connectivity (cont.)

Security Background

Security - httppppppppppp-upload: full drive exploit

Security - httppppppppppp-upload: full drive exploit (cont.)

Security - httppppppppppp-upload: full drive exploit (cont.)

Security - httppppppppppp-upload: full drive exploit (cont.)

Security - eatxmempp: CVE-2021-32918

Security - eatxmempp: CVE-2021-32918 (cont.)

Security - eatxmempp: CVE-2021-32918 (cont.)

Security - eatxmempp: CVE-2021-32918 (cont.)

Security - eatxmempp: CVE-2021-32918 (cont.)

Security - eatxmempp: CVE-2021-32918 (cont.)

Security - XEP-0156 _xmppconnect is vulnerable to MITM

Security - XEP-0156 _xmppconnect is vulnerable to MITM (cont.)

Security - XEP-0156 _xmppconnect is vulnerable to MITM (cont.)

xmpp-proxy high-level today

xmpp-proxy high-level today (cont.)

splitting the stream

testing all this

testing all this

xmpp-bench-proxy

Converse-Tauri

Java/Android bindings

What’s next for xmpp-proxy?

(not so) secret project

(not so) secret project (cont.)

Questions?