From XSLT code execution to Meterpreter shells

看板Bugtraq作者時間13年前 (2012/07/05 02:01), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串1/1
Hello, in the last weeks, I demonstrated at HackInTheBox Amsterdam and HackInParis a Metasploit module used to gain Meterpreter shells from XSLT vulnerabilities. Given the questions I received, I chose to publish a blog-post explaining the overall concept and some implementation details. The article is available here: http://www.agarri.fr/blog/ The vulnerable PHP and JSP applications used during the talk are included. Furthermore, the video of the HackInTheBox talk is online: http://www.youtube.com/watch?v=_0mNSAbsRaU
Regards, Nicolas Gr矇goire
文章代碼(AID): #1Fz8JUVi (Bugtraq)