Very creative way to turn Prototype Pollution into RCE in kibana - Bug Bounty Reports Explained
Автор: Bug Bounty Reports Explained
Загружено: 2020-12-05
Просмотров: 6167
📧 Subscribe to BBRE Premium: https://bbre.dev/premium
✉️ Sign up for the mailing list: https://bbre.dev/nl
📣 Follow me on Twitter: https://bbre.dev/tw
This video is an explanation of prototype pollution vulnerability in kibana that, in a super cool and very creative way, was used to achieve remote code execution in kibana software.
Blogpost:
https://research.securitum.com/protot...
Researcher's twitter:
/ securitymb
Follow me on twitter:
/ gregxsunday
Timestamps:
00:00 Intro
00:34 Prototype pollution
02:27 Vulnerability discovery
04:14 Exploitation
#rce #protoPollution
Доступные форматы для скачивания:
Скачать видео mp4
-
Информация по загрузке: