Hi Joshua, really liked your talk on this topic! Is it also possible to exploit this Apple Pay misconfiguration if the validationURL only triggers a blind SSRF? 
-
-
-
The merchant validation endpoints tend to be non-blind SSRF if you point them somewhere that returns JSON, since in the normal case they're expected to pass the JSON back to the frontend so it can complete the transaction. Conveniently, GCP/AWS metadata comes back as JSON.
- Još 2 druga odgovora
Novi razgovor -
-
-
This is super cool! I want to see more. If there is ever a video available, please share!
-
I'm not sure about recordings of the full presentation, but the slides and demo videos are up here: https://media.defcon.org/DEF%20CON%2027/DEF%20CON%2027%20presentations/ …
Kraj razgovora
Novi razgovor -
-
-
I’m glad I went to your talk, it ended up being my favorite of the day. Good learnings that I can take back to my job as a software engineer. Ty!
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
-
Čini se da učitavanje traje već neko vrijeme.
Twitter je možda preopterećen ili ima kratkotrajnih poteškoća u radu. Pokušajte ponovno ili potražite dodatne informacije u odjeljku Status Twittera.