<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>Posts on qtc&#39;s blog</title>
    <link>https://blog.tneitzel.eu/posts/</link>
    <description>Recent content in Posts on qtc&#39;s blog</description>
    <generator>Hugo -- gohugo.io</generator>
    <lastBuildDate>Thu, 30 Dec 2021 00:00:00 +0000</lastBuildDate><atom:link href="https://blog.tneitzel.eu/posts/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Attacking Java RMI via SSRF</title>
      <link>https://blog.tneitzel.eu/posts/01-attacking-java-rmi-via-ssrf/</link>
      <pubDate>Thu, 30 Dec 2021 00:00:00 +0000</pubDate>
      
      <guid>https://blog.tneitzel.eu/posts/01-attacking-java-rmi-via-ssrf/</guid>
      <description>During the last couple of years, SSRF vulnerabilities have become more and more popular and several high impact vulnerabilities have been identified. Possible targets in the backend range from HTTP based services like Solr, over cloud metadata services, up to more exotic targets like redis databases. In this blog post we discuss the SSRFibility of Java RMI and demonstrate how RMI services can be targeted via SSRF.
The SSRFibility of Java RMI  Java RMI is an object oriented RPC (Remote Procedure Call) mechanism that is available by default in most Java installations.</description>
    </item>
    
  </channel>
</rss>
