Other nomination
RCE through mangled WAR upload into Tomcat App Manager using PUT-in-Gopher-over-XXE
ZeroNights 2012 deck chaining local file read and SSRF into full compromise of ForgeRock OpenAM on Tomcat. Blind XXE lists directories and reads configs, then gopher carries an HTTP PUT that uploads a store-compressed WAR whose checksums Tomcat tolerates, giving RCE. Further slides force debug logging by CSRF, hijack admin sessions and dump the heap to recover the encryption key.
Record
- Researcher
- George Noseevich and Andrew Petukhov
- Published by
- slideshare.net
- Format
- Slides
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of George Noseevich and Andrew Petukhov, first published at the original source. Preserved copies are kept so the citation survives its host.