A JOURNEY FROM JNDI/LDAP MANIPULATION TO REMOTE CODE EXECUTION DREAM LAND Alvaro Muñoz (@pwntester) Oleksandr Mirosh Who are we ⢠Alvaro Muñoz (@pwntester) ⢠Principal Security Researcher, HPE Fortify ⢠Oleksandr Mirosh ⢠Senior QA Engineer, HPE Fortify Agenda ⢠Introduction to JNDI ⢠JNDI Injection ⢠RMI Vector ⢠Demo: EclipseLink/TopLink ⢠CORBA Vector ⢠LDAP Vector ⢠LDAP Entry Poisoning ⢠Demo
{{#tags}}- {{label}}
{{/tags}}