AEM Hacker - Approaching Adobe Experience Manager Webapps in Bug Bounty Programs

AEM Hacker - Approaching Adobe Experience Manager Webapps in Bug Bounty Programs

Bugcrowd via YouTube Direct link

Vectors

48 of 52

48 of 52

Vectors

Class Central Classrooms beta

YouTube videos curated by Class Central.

Classroom Contents

AEM Hacker - Approaching Adobe Experience Manager Webapps in Bug Bounty Programs

Automatically move to the next video in the Classroom when playback concludes

  1. 1 Intro
  2. 2 Why this talk?
  3. 3 Topics to discuss
  4. 4 Public VPD with AEM targets in scope
  5. 5 Personal achievements in 2018
  6. 6 Previous works
  7. 7 AEM architecture
  8. 8 Common AEM deployment
  9. 9 AEM Dispatcher bypasses
  10. 10 Using CVE-2016-0957
  11. 11 Bypasses for "interesting" servlets
  12. 12 Add multiple slashes
  13. 13 Using SSRF
  14. 14 AEM RCE bundle, build yourself For AEM 6.0 or newer
  15. 15 AEM hacker toolset
  16. 16 aem_hacker.py - checks 1/3
  17. 17 aem_discoverer.py
  18. 18 aem_enum.py
  19. 19 aem_ssrf2rce.py & aem_server.py
  20. 20 RCE via exposed Groovy console
  21. 21 RCE via ACS AEM Tools
  22. 22 How to get valid creds?
  23. 23 RCE via credentials of privileged user
  24. 24 RCE via uploading OSGI bundle
  25. 25 Author user
  26. 26 Non-privileged user
  27. 27 Tricks to get persistent XSS
  28. 28 Anonymous user & SVG
  29. 29 Anonymous user & HTML prop
  30. 30 Anonymous user & upload file
  31. 31 Extracting secrets from JCR
  32. 32 Why is it possible?
  33. 33 What to use
  34. 34 DefaultGetServlet - How to grab
  35. 35 DefaultGetServlet - What to grab
  36. 36 DefaultGetServlet - In the wild
  37. 37 QueryBuilder servlets
  38. 38 QueryBuilder - In the wild
  39. 39 Opensocial (Shindig) proxy
  40. 40 Reporting Services ProxyServlet
  41. 41 Salesforce SecretServlet
  42. 42 SiteCatalystServlet
  43. 43 Auto ProvisioningServlet
  44. 44 SSRF RCE
  45. 45 ExternalJobPostServlet
  46. 46 XXE via WebDAV
  47. 47 Check WebDAV support
  48. 48 Vectors
  49. 49 Video Player.swf
  50. 50 WCMDebugFilter
  51. 51 SuggestionHandlerServlet
  52. 52 Conclusion

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.