Two years ago, something very strange happened to me while working from my home network. I was exploiting a blind XXE vulnerability that required an external HTTP server to smuggle out files, so I spun up an AWS box and ran a simple Python webserver to receive the traffic from the vulnerable server.

This is actually nuts. I watched a video breakdown of this blog post and my jaw was on the floor. Super interesting stuff.

@Threen@aussie.zone
creator
link
fedilink
45M

Absolutely, it’s a great read. Could you link the video you watched?

@Threen@aussie.zone
creator
link
fedilink
45M

Thank you so much, I’ll check it out!

@dotslashme@infosec.pub
link
fedilink
English
25M

Really good writeup of a very interesting exploit.

Create a post

A nice place to discuss rumors, happenings, innovations, and challenges in the technology sphere. We also welcome discussions on the intersections of technology and society. If it’s technological news or discussion of technology, it probably belongs here.

Remember the overriding ethos on Beehaw: Be(e) Nice. Each user you encounter here is a person, and should be treated with kindness (even if they’re wrong, or use a Linux distro you don’t like). Personal attacks will not be tolerated.

Subcommunities on Beehaw:


This community’s icon was made by Aaron Schneider, under the CC-BY-NC-SA 4.0 license.

  • 1 user online
  • 53 users / day
  • 163 users / week
  • 617 users / month
  • 2.32K users / 6 months
  • 1 subscriber
  • 3.29K Posts
  • 67.1K Comments
  • Modlog