Top 10 winner
SOAPwn: Pwning .NET Framework Applications Through HTTP Client Proxies And WSDL
A missing cast in .NET Framework's SOAP HTTP client proxies lets a file:// or UNC URL make the proxy write its SOAP request body to disk instead of sending it. Attacker-supplied WSDL sets that URL and much of the body, giving arbitrary file write, webshell drops and pre-authentication RCE in enterprise products.
Record
- Researcher
- @chudyPB and Piotr Bazydlo (@chudyPB)
- Published by
- watchTowr Labs
- Date
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of @chudyPB and Piotr Bazydlo (@chudyPB), first published at the original source. Preserved copies are kept so the citation survives its host.