dns-exfiltration

1 article
sort: new top best
clear filter
0 7/10

Security researcher discovered an SSRF vulnerability in Yahoo! Guesthouse by finding a SAML endpoint through recon, then exploiting the BouncerSAMLRemoteSessionHost cookie which accepted arbitrary hostname values, causing the backend to make requests to attacker-controlled servers.

Yahoo! Guesthouse Th3G3nt3lman BouncerSAMLRemoteSessionHost https://gh.bouncer.login.yahoo.com/ https://alpha.keyserver.yahoo.com/saml dip2.gq1.yahoo.com
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 23 hours ago · details