2026-11-05 –, Room 2 Language: English
Modern web infrastructure doesn't route on IP addresses. Load balancers, proxies, and CDNs all make routing decisions based on application-layer content like Host headers, forwarding headers and request paths. This is how the web works at scale. But it creates a gap: the transport layer tells you exactly where a connection went, and above it, the web layer tells servers things the transport layer has no way to verify. I have been spending a lot of time in this territory while studying for my Burp Suite Certified Practitioner exam. The disagreement between what the IP layer says and what the web layer does is right there in a packet capture. This talk covers the main classes where the layers stop agreeing, and what each one looks like in Wireshark.
This talk walks through the main classes where this gap shows up, using real packet captures. For each one, I'll show what the disagreement looks like in Wireshark; where the transport layer and the web layer stop telling the same story, and what the server does as a result. No prior web security knowledge needed.
Katherine is a tech professional with 4 years of experience, having retrained in her 40s to become a Computer Expert, specialising in System Integration. Originally from New Zealand, she is currently based in Germany. During her training, she undertook a practicum at SevenShift, a boutique IoT cybersecurity company in Cologne that recognised her talent and dedication, ultimately hiring her. She is now employed there, where she is honing her skills and contributing to the company's security initiatives. Outside of her professional life, Katherine is a dedicated single mother to a teenager. She is a member of the Haecksen, the FINTA branch of the CCC, and a Chapter Leader of OWASP Cologne.