video thumbnail 12:41
Finding 0day in Apache APISIX During CTF (CVE-2022-24112)

2022-03-07

[public] 11.6K views, 4.47K likes, dislikes audio only

channel thumbLiveOverflow

In this video we perform a code audit of Api6 and discover a default configuration that can be escalated to remote code execution.

CVE-2022-24112: https://seclists.org/oss-sec/2022/q1/133

GitLab: https://liveoverflow.com/gitlab-11-4-7-remote-code-execution-real-world-ctf-2018/

Challenge files: https://github.com/chaitin/Real-World-CTF-4th-Challenge-Attachments/tree/master/API6

Chapters:

00:00 - Intro

01:09 - Initial Application Overview

02:15 - Discussing Approaches

03:56 - Reading Documentation

04:57 - Initial Attack Idea

06:15 - Identifying Attack Surface

08:46 - Discovering Batch Requests

09:18 - Bypassing X-Real-IP Header

10:15 - Testing the Exploit

11:11 - Reporting the Issue

12:16 - Outro

-=[ ā¤ļø Support ]=-

→ per Video: https://www.patreon.com/join/liveoverflow

→ per Month: https://www.youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w/join

-=[ šŸ• Social ]=-

→ Twitter: https://twitter.com/LiveOverflow/

→ Instagram: https://instagram.com/LiveOverflow/

→ Blog: https://liveoverflow.com/

→ Subreddit: https://www.reddit.com/r/LiveOverflow/

→ Facebook: https://www.facebook.com/LiveOverflow/


GitLab 11.4.7 Remote Code Execution - Real World CTF 2018 by LiveOverflow
/youtube/video/LrLJuyAdoAg
Intro
/youtube/video/yrCXamnX9No?t=0
Initial Application Overview
/youtube/video/yrCXamnX9No?t=69
Discussing Approaches
/youtube/video/yrCXamnX9No?t=135
Reading Documentation
/youtube/video/yrCXamnX9No?t=236
Initial Attack Idea
/youtube/video/yrCXamnX9No?t=297
Identifying Attack Surface
/youtube/video/yrCXamnX9No?t=375
Discovering Batch Requests
/youtube/video/yrCXamnX9No?t=526
Bypassing X-Real-IP Header
/youtube/video/yrCXamnX9No?t=558
Testing the Exploit
/youtube/video/yrCXamnX9No?t=615
Reporting the Issue
/youtube/video/yrCXamnX9No?t=671
Outro
/youtube/video/yrCXamnX9No?t=736
I’m moving, no videos sorry 17,538 views
/youtube/video/9CS3q0uG1LI
Support liveoverflow.com
https://liveoverflow.com/support
GitLab 11.4.7 Remote Code Execution - Real World CTF 2018 133,692 views
/youtube/video/LrLJuyAdoAg