Collected research
RCE through mangled WAR upload into Tomcat App Manager using PUT-in-Gopher-over-XXE
No locked doors, no windows barred: hacking OpenAM infrastructure
ZeroNights 2012 deck chaining local file read and SSRF into full compromise of ForgeRock OpenAM on Tomcat. Blind XXE lists directories and reads configs, then gopher carries an HTTP PUT that uploads a store-compressed WAR whose checksums Tomcat tolerates, giving RCE. Further slides force debug logging by CSRF, hijack admin sessions and dump the heap to recover the encryption key.
Record
- Document
- No locked doors, no windows barred: hacking OpenAM infrastructure
- Researcher
- George Noseevich and Andrew Petukhov
- Published by
- slideshare.net
- Format
- Slides
- Topic
- Injection
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of George Noseevich and Andrew Petukhov, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .