Web Hack List

Collected research

Jetty Features for Hacking Web Apps

A survey of Jetty behaviours useful against apps deployed on it: an error path that lists every deployed context, RCE by dropping a JSP shell, a WAR or a Jetty XML context file into the hot-deploy directory, XSS from uploads with extensions Jetty serves without a Content-Type, and WAF bypasses via path parameters, multipart charset encoding and boundary parsing quirks.

Record

Researcher
Mikhail Klyuchnikov and @m1ke_n1
Published by
PT SWARM
Topic
Other

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Mikhail Klyuchnikov and @m1ke_n1, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .