BlueHat IL 2023 - Daniel Abeles, Gal Goldshtein & Yuval Ostrovsky - The Story of a Backstage RCE

  Рет қаралды 566

Microsoft Israel R&D Center

Жыл бұрын

Behind the Curtains - The Story of a Backstage RCE
The recent rise in popularity of Developer portals, which integrate critical assets within the organization, makes them lucrative targets for threat actors. Having more than 19,000 stars on Github and used by various organizations, including American Airlines, Netflix and Epic Games, Backstage - a CNCF incubated project by Spotify, is one of the most popular open source platforms for building developer portals.
This presentation will showcase how we gained unauthenticated remote code execution rights on a Backstage application through a complex exploitation chain of various vulnerabilities. The chain includes a sandbox escape vulnerability we discovered along the way, improper authentication implementation, and the abuse of the integrated templating engine.
By the end of this presentation, you will have an understanding of the thought process that guided us through the research, including mapping the attack surfaces, choosing the components in the app that were most likely to become exploited, and how we managed to chain them all together to achieve the ultimate goal.

Пікірлер
Looks realistic #tiktok
00:22
Анастасия Тарасова
Рет қаралды 103 МЛН
Зачем он туда залез?
00:25
Vlad Samokatchik
Рет қаралды 2,6 МЛН
Incredible magic 🤯✨
00:53
America's Got Talent
Рет қаралды 81 МЛН
Samsung Galaxy 🔥 #shorts  #trending #youtubeshorts  #shortvideo ujjawal4u
0:10
Ujjawal4u. 120k Views . 4 hours ago
Рет қаралды 8 МЛН
iPhone socket cleaning #Fixit
0:30
Tamar DB (mt)
Рет қаралды 14 МЛН
Как распознать поддельный iPhone
0:44
PEREKUPILO
Рет қаралды 2 МЛН
Как удвоить напряжение? #электроника #умножитель
1:00
Hi Dev! – Электроника
Рет қаралды 861 М.
PART 52 || DIY Wireless Switch forElectronic Lights - Easy Guide!
1:01
HUBAB__OFFICIAL
Рет қаралды 62 МЛН