Web Hack List

Top 10 winner

Owning The Clout Through Server Side Request Forgery

Ben Sadeghipour - Owning The Clout Through Server Side Request Forgery - DEF CON 27 Conference

Server-side HTML to PDF generators render attacker markup in the server's own context, so an injected iframe or an escape from a style tag turns the export feature into server-side request forgery that reaches cloud metadata. WeasyPrint's attachment link embeds local files into the output PDF, and DNS rebinding defeats same-origin checks under headless Chrome, yielding cloud keys.

Record

Document
Ben Sadeghipour - Owning The Clout Through Server Side Request Forgery - DEF CON 27 Conference
Researcher
Ben Sadeghipour and Cody Brocious
Published by
DEF CON
Date
Format
Recording
Topic
Server

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Ben Sadeghipour and Cody Brocious, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .