Collected research
Jetty Features for Hacking Web Apps
A survey of Jetty behaviours useful against apps deployed on it: an error path that lists every deployed context, RCE by dropping a JSP shell, a WAR or a Jetty XML context file into the hot-deploy directory, XSS from uploads with extensions Jetty serves without a Content-Type, and WAF bypasses via path parameters, multipart charset encoding and boundary parsing quirks.
Record
- Researcher
- Mikhail Klyuchnikov and @m1ke_n1
- Published by
- PT SWARM
- Topic
- Other
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Mikhail Klyuchnikov and @m1ke_n1, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .