Top 10 winner
SOAPwn: Pwning .NET Framework Applications Through HTTP Client Proxies And WSDL
A missing cast in .NET Framework's SOAP HTTP client proxies lets a file:// or UNC URL make the proxy write its SOAP request body to disk instead of sending it. Attacker-supplied WSDL sets that URL and much of the body, giving arbitrary file write, webshell drops and pre-authentication RCE in enterprise products.
Record
- Researcher
- @chudyPB and Piotr Bazydlo (@chudyPB)
- Published by
- watchTowr Labs
- Date
- Topic
- HTTP
In the archive
Related sources
- Full research whitepaper Whitepaper
- Black Hat Europe 2025 | Pwning .NET Framework Applications Through HTTP Client Proxies And WSDL
Tags
This page is the archive's own catalogue record. The research is the work of @chudyPB and Piotr Bazydlo (@chudyPB), first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .