Web Hack List

Top 10 winner

Pwning via SSRF (memcached, php-fastcgi, etc)

ERPScan classify SSRF into trusted, simple, partial and full remote variants, then demonstrate XXE tunneling through the gopher URI scheme against SAP systems. Examples cover verb tampering, an ABAP kernel buffer overflow and SAP Gateway parameter changes; the paper documents one-packet and character restrictions.

Record

Researcher
Alexander Polyakov, Dmitry Chastukhin and Alexey Tyurin
Published by
ERPScan
Format
Whitepaper

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Alexander Polyakov, Dmitry Chastukhin and Alexey Tyurin, first published at the original source. Preserved copies are kept so the citation survives its host.