BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//conference.wireshark.org//sf26eu//talk//C9XATS
BEGIN:VTIMEZONE
TZID:CET
BEGIN:STANDARD
DTSTART:20001029T040000
RRULE:FREQ=YEARLY;BYDAY=-1SU;BYMONTH=10
TZNAME:CET
TZOFFSETFROM:+0200
TZOFFSETTO:+0100
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20000326T030000
RRULE:FREQ=YEARLY;BYDAY=-1SU;BYMONTH=3
TZNAME:CEST
TZOFFSETFROM:+0100
TZOFFSETTO:+0200
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
UID:pretalx-sf26eu-C9XATS@conference.wireshark.org
DTSTART;TZID=CET:20261105T101500
DTEND;TZID=CET:20261105T111500
DESCRIPTION:Modern web infrastructure doesn't route on IP addresses. Load b
 alancers\, proxies\, and CDNs all make routing decisions based on applicat
 ion-layer content like Host headers\, forwarding headers and request paths
 . This is how the web works at scale. But it creates a gap: the transport 
 layer tells you exactly where a connection went\, and above it\, the web l
 ayer tells servers things the transport layer has no way to verify. I have
  been spending a lot of time in this territory while studying for my Burp 
 Suite Certified Practitioner exam. The disagreement between what the IP la
 yer says and what the web layer does is right there in a packet capture. T
 his talk covers the main classes where the layers stop agreeing\, and what
  each one looks like in Wireshark.
DTSTAMP:20260922T091929Z
LOCATION:Room 2
SUMMARY:Web Vulnerabilities in Wireshark - Katherine Leese
URL:https://conference.wireshark.org/sf26eu/talk/C9XATS/
END:VEVENT
END:VCALENDAR
