Top 10 winner
Abusing CDNs with SSRF Flash and DNS
Black Hat USA (2015) - Bypass Surgery - Abusing CDNs with SSRF Flash and DNS - 06Aug2015
Combines DNS reconnaissance, Akamai EdgeSuite’s legacy ARLv1 fetching, and vulnerable FlowPlayer plugin loading. ARLv1 can place a whitelisted FlowPlayer SWF under a trusted CDN subdomain; attacker-loaded plugins then use Flash crossdomain.xml trust to make authenticated requests. Also demonstrates three FlowPlayer URL-check bypasses, including protocol-relative URLs, triple-slash parsing and an open redirect.
Record
- Document
- Black Hat USA (2015) - Bypass Surgery - Abusing CDNs with SSRF Flash and DNS - 06Aug2015
- Researcher
- Mike Brooks and Matthew Bryant
- Published by
- Bishop Fox
- Date
- Format
- Recording
- Topic
- HTTP
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Mike Brooks and Matthew Bryant, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .