Web Hack List

Collected research

RCE through mangled WAR upload into Tomcat App Manager using PUT-in-Gopher-over-XXE

No locked doors, no windows barred: hacking OpenAM infrastructure

ZeroNights 2012 deck chaining local file read and SSRF into full compromise of ForgeRock OpenAM on Tomcat. Blind XXE lists directories and reads configs, then gopher carries an HTTP PUT that uploads a store-compressed WAR whose checksums Tomcat tolerates, giving RCE. Further slides force debug logging by CSRF, hijack admin sessions and dump the heap to recover the encryption key.

Record

Document
No locked doors, no windows barred: hacking OpenAM infrastructure
Researcher
George Noseevich and Andrew Petukhov
Published by
slideshare.net
Format
Slides
Topic
Injection

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of George Noseevich and Andrew Petukhov, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .