
Patrik Fehrenbach
@itsecurityguard
rɪsˈpɒnsəbl dɪsˈkləʊʒə
wss.sh
huntdb.com
ID: 1089376824
https://blog.wss.sh 14-01-2013 15:51:37
4,4K Tweet
30,30K Followers
282 Following


We (+sagitz Ronen Shustin Hillai Ben-Sasson) found a series of unauthenticated RCEs in core @KubernetesIO project "Ingress-NGINX". The impact? From zero permissions ➡️ to complete cluster takeover 🤯 This is the story of #IngressNightmare 🧵⬇️














How do we turn bad SSRF (blind) into good SSRF (full response)? The Assetnote Security Research team at Searchlight Cyber used a novel technique involving HTTP redirect loops and incremental status codes that leaked the full HTTP resp. It may work elsewhere! slcyber.io/assetnote-secu…


