Finding 0day in Apache APISIX During CTF (CVE-2022-24112)
In this video we perform a code audit of Api6 and discover a default configuration that can be escalated to remote code execution.
CVE-2022-24112:
GitLab:
Challenge files:
Chapters:
00:00 - Intro
01:09 - Initial Application Overview
02:15 - Discussing Approaches
03:56 - Reading Documentation
04:57 - Initial Attack Idea
06:15 - Identifying Attack Surface
08:46 - Discovering Batch Requests
09:18 - Bypassing X-Real-IP Header
10:15 - Testing the Exploit
11:11 - Reporting the Issue
12:16 - Outro
-=[ ❤️ Support ]=-
→ per Video:
→ per Month:
-=[ 🐕 Social ]=-
→ Twitter:
→ Instagram:
→ Blog:
→ Subreddit: https
1 view
0
0
9 months ago 00:47:11 1
100 Days in Minecraft: Beta
1 year ago 00:32:36 1
#HITB2023HKT D1T1 - Extracting Info From Automotive Internet Units - A. Kondikov & Y. Serdyuk
1 year ago 01:21:33 1
Bandimere Speedway CLOSES! Midnight Purple Chevy + 200MPH RECORD PASS! (RMRW Day 5 & 6)