$12,000 Grafana SSRF in Gitlab - Bug Bounty Reports Explained
Автор: Bug Bounty Reports Explained
Загружено: 2020-10-11
Просмотров: 8315
Описание:
📧 Subscribe to BBRE Premium: https://bbre.dev/premium
✉️ Sign up for the mailing list: https://bbre.dev/nl
📣 Follow me on Twitter: https://bbre.dev/tw
This video is about Grafana SSRF vulnerability that was reported to Gitlab bug bounty program on Hackerone. The reward for this bug was $12,000, as it was possible to request AWS metadata endpoint.
Follow me on twitter:
/ gregxsunday
Report:
https://hackerone.com/reports/878779
Justin Gardner:
/ rhynorater
His talk on this topic - speaks about more ways of exploitation:
writeup:
https://rhynorater.github.io/CVE-2020...
video:
• h@cktivitycon 2020: Graphing Out Internal ...
slides: https://docs.google.com/presentation/...
Fragments of vulnerable Grafana source code:
https://github.com/grafana/grafana/bl...
https://github.com/grafana/grafana/bl...
Timestamps:
00:00 Intro
00:24 Redirect chain
03:56 Payload
04:24 Outro
#grafana #ssrf #gitlab #bug #bounty
Повторяем попытку...
Доступные форматы для скачивания:
Скачать видео
-
Информация по загрузке: