Hackfest 2015: Nicolas Grégoire presented "Server Side Browsing"

Опубликовано: 10 Март 2026
на канале: Hackfest Communication
2,756
52

Talk Description:
SSRF vulnerabilities (aka CWE-918) allows attackers to submit arbitrary URL to vulnerable applications, and have the application (or one of its components) browse this URL. The talk describes my latest findings regarding this narrow field of AppSec. Of course, being under NDA during my penetration tests, I’ll only covering bugs reported to bounties
programs. That includes Yahoo, Facebook, Prezi, PayPal, Stripe, CoinBase, and more!

Highlights: I was able to compromise some large service providers and earned around 50,000$ for that. Several blacklists were bypassed using little-known quirks in the parsing of URL.

Presented by:
Hackfest communication - http://www.hackfest.ca