Web Hack List

Collected research

Pivoting from blind SSRF to RCE with HashiCorp Consul

A SOAP feature that fetched a user-supplied URL gave blind SSRF with no response returned. The Ruby HTTP client did not reject CRLF sequences in the URL, letting a second attacker-written request be appended to the hardcoded POST. That was used to send an HTTP PUT to a localhost HashiCorp Consul agent, whose check-register endpoint is unauthenticated by default and runs shell commands.

Record

Researcher
Peter Adkins
Published by
kernelpicnic.net
Topic
Server

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Peter Adkins, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .