Web Hack List

Top 10 winner

Abusing CDNs with SSRF Flash and DNS

Black Hat USA (2015) - Bypass Surgery - Abusing CDNs with SSRF Flash and DNS - 06Aug2015

Combines DNS reconnaissance, Akamai EdgeSuite’s legacy ARLv1 fetching, and vulnerable FlowPlayer plugin loading. ARLv1 can place a whitelisted FlowPlayer SWF under a trusted CDN subdomain; attacker-loaded plugins then use Flash crossdomain.xml trust to make authenticated requests. Also demonstrates three FlowPlayer URL-check bypasses, including protocol-relative URLs, triple-slash parsing and an open redirect.

Record

Document
Black Hat USA (2015) - Bypass Surgery - Abusing CDNs with SSRF Flash and DNS - 06Aug2015
Researcher
Mike Brooks and Matthew Bryant
Published by
Bishop Fox
Date
Format
Recording
Topic
HTTP

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Mike Brooks and Matthew Bryant, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .