Collected research
How I Hacked StackOverflow
Anatomy of an Attack: How I Hacked StackOverflow
An SSH-tunnelled Squid proxy stamped X-Forwarded-For: 127.0.0.1 on the author's requests, and StackExchange's IIS was configured to rewrite Remote_Addr from that header. The application checked the right variable, so the proxy alone granted full chat admin and database query access. The lesson drawn is that server and application must not disagree about which header is trusted.
Record
- Document
- Anatomy of an Attack: How I Hacked StackOverflow
- Researcher
- Anthony Ferrara
- Published by
- blog.ircmaxell.com
- Topic
- Other
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Anthony Ferrara, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .