DEF CON 27 - Ben Sadeghipour - Owning The Clout Through Server-Side Request Forgery

Опубликовано: 13 Март 2026
на канале: HackersOnBoard
175
3

With how many apps are running in the cloud, hacking these instances becomes easier with a simple vulnerability due to an unsanitized user input. In this talk, we’ll discuss a number of different methods that helped us exfil data from different applications using Server-Side Request Forgery (SSRF). Using these methods, we were able to hack some of the major transportation, hospitality, and social media companies and make $50,000 in rewards in 3 months.