Web Hack List

Collected research

Piercing the Veil: Server Side Request Forgery to NIPRNet access

Two Department of Defense Jira instances exposed the unauthenticated oauth icon-uri endpoint to server-side request forgery, which was used to read AWS instance metadata and to reach internal services on NIPRNet. Verbose stack traces and response-time differences acted as an oracle for scanning internal ports and protocols.

Record

Researcher
Alyssa Herrera and @Alyssa_Herrera_
Published by
Medium
Date
Topic
Server

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Alyssa Herrera and @Alyssa_Herrera_, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .