Arbitrary Code Injection Via Groovy Script Parser (SoapUI)

Publicado em: 11 Dezembro 2023
no canal de: InfoSecHac
230
16

🔐 Dive into the realm of cybersecurity with our exploration of the CVE-2014-1202 vulnerability in SoapUI. In this video, we guide you through the process of bypassing the mitigation for CVE-2014-1202 using powerful instrumentation techniques. Discover how older versions of SoapUI lack proper validation, potentially exposing code injection issues when loading XML/WSDL with a Groovy script.

Don't miss out on this crucial insight into cybersecurity and vulnerability mitigation – watch now! 🚀

What is Groovy?
Groovy is a scripting language for the Java platform, serving as a superset of Java. This means that Java programs can seamlessly run in the Groovy environment. While Groovy can be a powerful tool, it is imperative to use it responsibly and securely. Always ensure that input validation and sanitization measures are in place to prevent code injection vulnerabilities.

To reproduce this issue, I attempted it with the latest version of SoapUI (5.7.2). You can download it from the following link: https://www.soapui.org/downloads/late...

Project Setup and Instrumentation using Fusion Lite Project Manager:

For more information about Fusion, visit the following URL:
https://www.iappsecure.com/products/

For a detailed description of the vulnerability, visit this URL:
https://spookhorror.gitbook.io/blogs-1/

Download the malicious WSDL file of the previous payload here: https://raw.githubusercontent.com/spo...

#cybersecurity #VulnerabilityMitigation #Instrumentation #SoapUI #CodeInjection #CVE2014-1202


Nesta página do site você pode assistir ao vídeo on-line Arbitrary Code Injection Via Groovy Script Parser (SoapUI) duração hora minuto segundo em boa qualidade , que foi baixado pelo usuário InfoSecHac 11 Dezembro 2023, compartilhe o link com seus amigos e conhecidos, no youtube este vídeo já foi visto 230 vezes e gostou 16 espectadores. Boa visualização!