Arbitrary Code Injection Via Groovy Script Parser (SoapUI)

Publié le: 11 décembre 2023
sur la chaîne: InfoSecHac
230
16

🔐 Dive into the realm of cybersecurity with our exploration of the CVE-2014-1202 vulnerability in SoapUI. In this video, we guide you through the process of bypassing the mitigation for CVE-2014-1202 using powerful instrumentation techniques. Discover how older versions of SoapUI lack proper validation, potentially exposing code injection issues when loading XML/WSDL with a Groovy script.

Don't miss out on this crucial insight into cybersecurity and vulnerability mitigation – watch now! 🚀

What is Groovy?
Groovy is a scripting language for the Java platform, serving as a superset of Java. This means that Java programs can seamlessly run in the Groovy environment. While Groovy can be a powerful tool, it is imperative to use it responsibly and securely. Always ensure that input validation and sanitization measures are in place to prevent code injection vulnerabilities.

To reproduce this issue, I attempted it with the latest version of SoapUI (5.7.2). You can download it from the following link: https://www.soapui.org/downloads/late...

Project Setup and Instrumentation using Fusion Lite Project Manager:

For more information about Fusion, visit the following URL:
https://www.iappsecure.com/products/

For a detailed description of the vulnerability, visit this URL:
https://spookhorror.gitbook.io/blogs-1/

Download the malicious WSDL file of the previous payload here: https://raw.githubusercontent.com/spo...

#cybersecurity #VulnerabilityMitigation #Instrumentation #SoapUI #CodeInjection #CVE2014-1202


Sur cette page du site, vous pouvez voir la vidéo en ligne Arbitrary Code Injection Via Groovy Script Parser (SoapUI) durée heure minute seconde en bonne qualité , qui a été Téléchargé par l'utilisateur InfoSecHac 11 décembre 2023, Partagez le lien avec vos amis et connaissances, sur youtube cette vidéo a déjà été regardée 230 fois et il a aimé 16 téléspectateurs. Bon visionnage!