Web Hack List

Collected research

Compromising an unreachable Solr Serve

Agarri : Sécurité informatique offensive

Gregoire turns an XXE in a Java app into compromise of an unreachable Solr server: the XXE port-scans internally, finds Solr on 8983, then abuses Solr's XSLT response writer with a tr=../../ traversal to load an uploaded stylesheet and execute Java (CVE-2013-6397). The capture is the whole blog index, so it also carries Perl Storable, AMF XXE, Redis and XSLT-fuzzing posts.

Record

Document
Agarri : Sécurité informatique offensive
Researcher
Nicolas Grégoire
Published by
agarri.fr
Topic
Other

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Nicolas Grégoire, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .