Перейти к содержимому

A New Era of SSRF - Exploiting URL Parser in Trending Programming Languages!

Black Hat

0:00 / 0:00

A New Era of SSRF - Exploiting URL Parser in Trending Programming Languages!

26 309 просмотров · 6 лет назад
Black Hat
280 тыс. подписчиков
26 309 просмотров · 6 лет назад
We propose a new exploit technique that brings a whole-new attack surface to bypass SSRF (Server Side Request Forgery) protections. This is a very general attack approach, in which we used in combination with our own fuzzing tool to discover many 0days in built-in libraries of very widely-used programming languages, including Python, PHP, Perl, Ruby, Java, JavaScript, Wget and cURL. The root cause of the problem lies in the inconsistency of URL parsers and URL requesters. By Orange Tsai Full Abstract & Presentation Materials: https://www.blackhat.com/us-17/briefi...