Marco Ivaldi · @raptor
1609 followers · 843 posts · Server infosec.exchange

Bypassing OGNL sandboxes for fun and charities

// by @pwntester @githubsecurity

“Object Graph Notation Language ( ) is a popular, Java-based, expression language used in popular frameworks and applications, such as Apache and Atlassian . Learn more about bypassing certain OGNL injection protection mechanisms including those used by Struts and Atlassian Confluence, as well as different approaches to analyzing this form of protection so you can harden similar systems.”

github.blog/2023-01-27-bypassi

#ognl #struts #confluence

Last updated 3 years ago

ITSEC News · @itsecbot
687 followers · 32461 posts · Server schleuss.online

PoC Exploit Targeting Apache Struts Surfaces on GitHub - Researchers have discovered freely available PoC code and exploit that can be used to attack unpat... threatpost.com/poc-exploit-git -graphnavigationlanguage -of-concept -2019-0230 -2019-0233

#poc #dos #ognl #hacks #github #websecurity #cve #apachestruts2 #vulnerabilities #proof #apachestrutssecurityteam #object

Last updated 5 years ago