Arbitrary Code Injection Via Groovy Script Parser (SoapUI)

Pubblicato il: 11 dicembre 2023
sul canale di: InfoSecHac
230
16

🔐 Dive into the realm of cybersecurity with our exploration of the CVE-2014-1202 vulnerability in SoapUI. In this video, we guide you through the process of bypassing the mitigation for CVE-2014-1202 using powerful instrumentation techniques. Discover how older versions of SoapUI lack proper validation, potentially exposing code injection issues when loading XML/WSDL with a Groovy script.

Don't miss out on this crucial insight into cybersecurity and vulnerability mitigation – watch now! 🚀

What is Groovy?
Groovy is a scripting language for the Java platform, serving as a superset of Java. This means that Java programs can seamlessly run in the Groovy environment. While Groovy can be a powerful tool, it is imperative to use it responsibly and securely. Always ensure that input validation and sanitization measures are in place to prevent code injection vulnerabilities.

To reproduce this issue, I attempted it with the latest version of SoapUI (5.7.2). You can download it from the following link: https://www.soapui.org/downloads/late...

Project Setup and Instrumentation using Fusion Lite Project Manager:

For more information about Fusion, visit the following URL:
https://www.iappsecure.com/products/

For a detailed description of the vulnerability, visit this URL:
https://spookhorror.gitbook.io/blogs-1/

Download the malicious WSDL file of the previous payload here: https://raw.githubusercontent.com/spo...

#cybersecurity #VulnerabilityMitigation #Instrumentation #SoapUI #CodeInjection #CVE2014-1202


In questa pagina del sito puoi guardare il video online Arbitrary Code Injection Via Groovy Script Parser (SoapUI) della durata di ore minuti seconda in buona qualità , che l'utente ha caricato InfoSecHac 11 dicembre 2023, condividi il link con amici e conoscenti, su youtube questo video è già stato visto 230 volte e gli è piaciuto 16 spettatori. Buona visione!