Web Hack List

Top 10 winner

Attacking Secondary Contexts in Web Applications

When an application forwards a request to a second internal API, encoded traversal in the user-controlled part of the path rewrites the internal route. The talk shows reading other users' invoices and payment methods, reaching internal services through proxies, and an Authy 2FA bypass where any endpoint returning a success body satisfies the check.

Record

Researcher
Sam Curry
Published by
Kernelcon
Format
Slides
Topic
Other

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Sam Curry, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .