More dates

Payment plans

How does it work?

  • Reserve your order today and pay over time in regular, automatic payments.
  • You’ll receive your tickets and items once the final payment is complete.
  • No credit checks or third-party accounts - just simple, secure, automatic payments using your saved card.

WS2 - From Prompt to PWN: Exploiting LLM Powered Web Applications with OWASP Techniques

Share
DEF CON Workshops
Add to calendar
 

Description

Instructed by:  Abhinav  Verma

Level of Difficulty: Beginner, Intermediate, Advanced

Abstract:

This hands-on workshop explores the offensive security of AI-powered applications where Large Language Models connect to real tools via MCP (Model Context Protocol) servers. Over four hours, participants attack 11 purpose-built AI agents across 9 exercises, exploiting vulnerabilities mapped to the OWASP Top 10 for LLM Applications 2025.

You will perform prompt injection (direct and indirect via RAG poisoning), force AI agents to generate malicious SQL/NoSQL queries through MCP tool interfaces, chain path traversal and SSRF through tool-calling parameters, abuse excessive agency via MCP-exposed CRUD operations, trigger stored XSS through LLM output, and achieve remote code execution via a poisoned supply chain, all through natural language conversation.

This workshop is ideal for red teamers, penetration testers, security engineers, and developers building with LLMs. No prior AI or ML experience is required; every technique is demonstrated before the hands-on lab. Just bring a laptop with a browser.

You walk away with practical experience exploiting 93 attack objectives against live LLM agents, a clear understanding of how traditional web vulnerabilities are amplified through AI tool-calling architectures, and the instincts to spot these risks in your own AI deployments.

Pre-Requisites:

Basic familiarity with web application concepts (HTTP requests, HTML forms, browser developer tools). Understanding of at least one common web vulnerability such as SQL injection, XSS, or SSRF at a conceptual level. No machine learning, AI, Python, or MCP protocol experience required. No prior prompt engineering knowledge needed. Comfort using a web browser and reading JSON responses is sufficient. Students who have used Burp Suite, OWASP ZAP, or browser DevTools will have an advantage, but these tools are not required. All attacks are performed through the platform's chat interfaces.

Powered by

Tickets for good, not greed Humanitix dedicates 100% of profits from booking fees to charity

Register

This event has passed

Register

This event has passed
DEF CON Workshops