A New Era of SSRF - Exploiting URL Parser in Trending Programming Languages!
Автор: Black Hat
Загружено: 2020-01-08
Просмотров: 25461
Описание:
We propose a new exploit technique that brings a whole-new attack surface to bypass SSRF (Server Side Request Forgery) protections. This is a very general attack approach, in which we used in combination with our own fuzzing tool to discover many 0days in built-in libraries of very widely-used programming languages, including Python, PHP, Perl, Ruby, Java, JavaScript, Wget and cURL. The root cause of the problem lies in the inconsistency of URL parsers and URL requesters.
By Orange Tsai
Full Abstract & Presentation Materials:
https://www.blackhat.com/us-17/briefi...
Повторяем попытку...
Доступные форматы для скачивания:
Скачать видео
-
Информация по загрузке: