Web Hack List

Collected research

Java JAR Attacks and Features

The Java runtime will load a JAR appended to a JPEG, so a file that passes image header checks is still executable byte code, and an applet runs in the sandbox of its codebase host. pdp chains the two: upload the polyglot to a target that accepts images, embed it from anywhere, and any internal visitor becomes a socket proxy onto the target's firewalled ports such as MSSQL.

Record

Researcher
pdp
Published by
gnucitizen.org
Topic
Server

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of pdp, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .