Top 10 winner
Abusing CDNs with SSRF Flash and DNS
Combines DNS reconnaissance, Akamai EdgeSuite’s legacy ARLv1 fetching, and vulnerable FlowPlayer plugin loading. ARLv1 can place a whitelisted FlowPlayer SWF under a trusted CDN subdomain; attacker-loaded plugins then use Flash crossdomain.xml trust to make authenticated requests. Also demonstrates three FlowPlayer URL-check bypasses, including protocol-relative URLs, triple-slash parsing and an open redirect.
Record
- Researcher
- Mike Brooks and Matthew Bryant
- Published by
- Bishop Fox
- Date
- Format
- Recording
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Mike Brooks and Matthew Bryant, first published at the original source. Preserved copies are kept so the citation survives its host.