Web Hack List

Collected research

Exploiting the Unexploitable Insights from the Kibana Bug Bounty

Kibana's synthetic-monitoring feature runs user-pasted JavaScript by design, and NET_RAW on the container turned that into ARP spoofing of the cluster. CodeQL then found server-side prototype pollution in the kibana.yml parser, whose dotted-key expansion writes through __proto__, and in a DELETE uptime handler. Pollution crashes Kibana within a second, so the gadgets - require()'s package.json fields, nodemailer's sendmail path - are reached by flooding requests around the polluting one.

Record

Researcher
Mikhail Shcherbakov
Published by
media.defcon.org
Format
Whitepaper
Topic
Other

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Mikhail Shcherbakov, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .