Главная
Study mode:
on
1
Intro
2
Orange Tsai
3
Agenda
4
Polyglot URL path
5
Why path normalization
6
Can you spot the vulnerability?
7
Nginx off-by-slash fail
8
How to find this problem?
9
Spring Oday - CVE-2018-1271
10
Bonus on Spark framework
11
Rails Oday - CVE-2018-3760
12
For the RCE lover
13
URL path parameter
14
When reverse proxy meets...
15
How danger it could be?
16
Uber bounty case
17
Bynder RCE case study
18
Inconsistency to ACL bypass
19
Misa New Password
20
Misconfiguration to auth bypass
21
Log injection to RCE
22
Private bounty case
23
Amazon RCE case study
24
Path normalization bug leads to ACL bypass
25
Seam Feature
26
Code reuse bug leads to Expression Language injection
27
EL blacklist bypassed leads to Remote Code Execution
28
Mitigation
29
Summary
Description:
Explore path normalization vulnerabilities and their exploitation in this conference talk from Hack.lu 2018. Delve into various case studies, including Nginx off-by-slash failures, Spring and Rails 0days, and RCE vulnerabilities in Uber and Amazon. Learn about polyglot URL paths, spotting vulnerabilities, and techniques for finding these issues. Examine the dangers of reverse proxy interactions, ACL bypasses through inconsistencies, and authentication bypasses via misconfigurations. Discover how log injection can lead to RCE and how code reuse bugs can result in Expression Language injection. Gain insights into mitigation strategies and summarize key takeaways for improving web application security.

Take Your Path Normalization Off and Pop 0days Out

Cooper
Add to list
0:00 / 0:00