Arbitrary Code Injection Via Groovy Script Parser (SoapUI)

Published: 11 December 2023
on channel: InfoSecHac
230
16

🔐 Dive into the realm of cybersecurity with our exploration of the CVE-2014-1202 vulnerability in SoapUI. In this video, we guide you through the process of bypassing the mitigation for CVE-2014-1202 using powerful instrumentation techniques. Discover how older versions of SoapUI lack proper validation, potentially exposing code injection issues when loading XML/WSDL with a Groovy script.

Don't miss out on this crucial insight into cybersecurity and vulnerability mitigation – watch now! 🚀

What is Groovy?
Groovy is a scripting language for the Java platform, serving as a superset of Java. This means that Java programs can seamlessly run in the Groovy environment. While Groovy can be a powerful tool, it is imperative to use it responsibly and securely. Always ensure that input validation and sanitization measures are in place to prevent code injection vulnerabilities.

To reproduce this issue, I attempted it with the latest version of SoapUI (5.7.2). You can download it from the following link: https://www.soapui.org/downloads/late...

Project Setup and Instrumentation using Fusion Lite Project Manager:

For more information about Fusion, visit the following URL:
https://www.iappsecure.com/products/

For a detailed description of the vulnerability, visit this URL:
https://spookhorror.gitbook.io/blogs-1/

Download the malicious WSDL file of the previous payload here: https://raw.githubusercontent.com/spo...

#cybersecurity #VulnerabilityMitigation #Instrumentation #SoapUI #CodeInjection #CVE2014-1202


On this page of the site you can watch the video online Arbitrary Code Injection Via Groovy Script Parser (SoapUI) with a duration of hours minute second in good quality, which was uploaded by the user InfoSecHac 11 December 2023, share the link with friends and acquaintances, this video has already been watched 230 times on youtube and it was liked by 16 viewers. Enjoy your viewing!