Breaking Parser Logic: Take Your Path Normalization off and Pop 0days Out! @HackersOnBoard
Breaking Parser Logic: Take Your Path Normalization off and Pop 0days Out!  @HackersOnBoard
Uploaded October 2019 | Updated September 2026, 4 hours ago
Black Hat USA 2018
We propose a new exploit technique that brings a whole-new attack surface to defeat path normalization, which is complicated in implementation due to many implicit properties and edge cases. This complication, being under-estimated or ignored by developers for a long time, has made our proposed attack vector possible, lethal, and general. Therefore, many 0days have been discovered via this approach in popular web frameworks written in trending programming languages, including Python, Ruby, Java, and JavaScript.

Being a very fundamental problem that exists in path normalization logic, sophisticated web frameworks can also suffer. For example, we've found various 0days on Java Spring Framework, Ruby on Rails, Next.js, and Python aiohttp, just to name a few. This general technique can also adapt to multi-layered web architecture, such as using Nginx or Apache as a proxy for Tomcat. In that case, reverse proxy protections can be bypassed. To make things worse, we're able to chain path normalization bugs to bypass authentication and achieve RCE in real world Bug Bounty Programs. Several scenarios will be demonstrated to illustrate how path normalization can be exploited to achieve sensitive information disclosure, SMB-Relay and RCE.

Understanding the basics of this technique, the audience won't be surprised to know that more than 10 vulnerabilities have been found in sophisticated frameworks and multi-layered web architectures aforementioned via this technique.
Breaking Parser Logic: Take Your Path Normalization off and Pop 0days Out!Black Hat USA 2018 - From Bot to Robot How Abilities and Law Change with PhysicalityDEF CON 27 - Campbell Murray - GSM We Can Hear Everyone NowDEF CON 27 - Jayson Grace - MOSE Using Configuration Management for EvilDEF CON 27 - Jens Muller - Re Whats up Johnny Covert Content Attacks on Email End-to-End EncryptionBlack Hat USA 2018 - Mainframe [z/OS] Reverse Engineering and Exploit DevelopmentDetecting Malicious Cloud Account Behavior A Look at the New Native Platform CapabilitiesDEF CON 27 - Zombie Ant Farm Practical Tips for Playing Hide and Seek with Linux EDRsDEF CON 27 - State of DNS Rebinding Attack & Prevention Techniques and the Singularity of OriginDEF CON 27 - droogie - Go NULL Yourself or How I Learned to Start Worrying While Getting FinedDEF CON 27 - XiaoHuiHui - All the 4G Modules Could Be HackedDEF CON 27 - Leon Jacobs - Meticulously Modern Mobile Manipulations
HackersOnBoard |

Breaking Parser Logic: Take Your Path Normalization off and Pop 0days Out!

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER