Web Hack List

Collected research

Fear the EAR: Execution After Redirect

UCSB’s International Capture The Flag Competition 2010 Challenge 6: Fear The EAR

A walkthrough of an iCTF 2010 challenge built to publicise Execution After Redirect, where server code keeps running past an intended termination point and leaks the response body alongside a 302. Browsers and tools such as wget and curl follow the redirect and hide the leaked page, so the flaw is hard to spot; only 12 of 34 exposed teams noticed it.

Record

Document
UCSB’s International Capture The Flag Competition 2010 Challenge 6: Fear The EAR
Published by
bryceboe.com
Topic
Other

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of bryceboe.com, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .