Top 10 winner
Exploiting Null Byte Buffer Overflow for a $40,000 bounty
A registration form passed a user string and its length to a back-end C routine; null bytes were stripped in transit but the length was not, so the C side read past the shortened string. Repeating a POST full of %00 bytes returned megabytes of adjacent server memory, including RSA private keys, other users' page DOMs, plaintext credentials and internal HTTP requests.
Record
- Researcher
- Sam Curry and @samwcyo
- Date
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Sam Curry and @samwcyo, first published at the original source. Preserved copies are kept so the citation survives its host.