Collected research
Pivoting from blind SSRF to RCE with HashiCorp Consul
A SOAP feature that fetched a user-supplied URL gave blind SSRF with no response returned. The Ruby HTTP client did not reject CRLF sequences in the URL, letting a second attacker-written request be appended to the hardcoded POST. That was used to send an HTTP PUT to a localhost HashiCorp Consul agent, whose check-register endpoint is unauthenticated by default and runs shell commands.
Record
- Researcher
- Peter Adkins
- Published by
- kernelpicnic.net
- Topic
- Server
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Peter Adkins, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .