Web Hack List

Later archive addition

Fear the EAR: Execution After Redirect

A walkthrough of an iCTF 2010 challenge built to publicise Execution After Redirect, where server code keeps running past an intended termination point and leaks the response body alongside a 302. Browsers and tools such as wget and curl follow the redirect and hide the leaked page, so the flaw is hard to spot; only 12 of 34 exposed teams noticed it.

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of its author, first published at the original source. Preserved copies are kept so the citation survives its host.