https://github.com/veracode-research/solr-injection
A brand new vulnerability - Apache Solr Injection, as well as new ways to RCE in this innocent looking search engine.
Here is the whitepaper and the video from my presentation at DEFCON 27.
https://github.com/veracode-research/solr-injection
A brand new vulnerability - Apache Solr Injection, as well as new ways to RCE in this innocent looking search engine.
Here is the whitepaper and the video from my presentation at DEFCON 27.
https://www.veracode.com/blog/research/exploiting-spring-boot-actuators
I wrote this article while working at the Veracode Research team.
https://www.veracode.com/blog/research/exploiting-jndi-injections-java
I wrote this article while working at the Veracode Research team.