Top 10 winner
Unauthenticated RCE on MobileIron MDM
How I Hacked Facebook Again! Unauthenticated RCE on MobileIron MDM
Chains flaws in MobileIron MDM into unauthenticated remote code execution: an Apache rewrite ACL is stepped around with a path-normalisation trick to reach a Hessian deserialization endpoint, and a new Groovy MethodClosure gadget replaces the blocked JNDI route on hosts with no outbound access. Used to get a shell on an unpatched Facebook server.
Record
- Document
- How I Hacked Facebook Again! Unauthenticated RCE on MobileIron MDM
- Researcher
- Orange Tsai
- Published by
- Orange Tsai
- Date
- Topic
- Server
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Orange Tsai, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .