Attacking Secondary Contexts in Web Applications - Sam Curry

Поділитися
Вставка
  • Опубліковано 28 січ 2025

КОМЕНТАРІ • 4

  • @internetdoggo4839
    @internetdoggo4839 3 роки тому +2

    Very cool talk. I had never heard of secondary context

  • @markusjohansson2165
    @markusjohansson2165 3 роки тому +12

    Sometimes ; - semicolon, can be useful. If the frontend web server don't interpret path parameters but the secondary one does, you can request /path/..;/ . Browsers and front end web server won't try to normalize the URL but the second server will treat ..;/ as ../

    • @-bubby9633
      @-bubby9633 2 роки тому

      Yup I've used this trick a fair bit before! It especially works well on servers with Tomcat on the backend as Tomcat interprets path parameters

  • @theomidtabei
    @theomidtabei 3 місяці тому +1

    💙💙💙