Top 10 winner
Attacking Secondary Contexts in Web Applications
When an application forwards a request to a second internal API, encoded traversal in the user-controlled part of the path rewrites the internal route. The talk shows reading other users' invoices and payment methods, reaching internal services through proxies, and an Authy 2FA bypass where any endpoint returning a success body satisfies the check.
Record
- Researcher
- Sam Curry
- Published by
- Kernelcon
- Format
- Slides
- Topic
- Other
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Sam Curry, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .