DEF CON 27 - Joshua Maddux - API-Induced SSRF How Apple Pay Scattered Vulnerabilities Across the Web @HackersOnBoard
DEF CON 27 - Joshua Maddux - API-Induced SSRF How Apple Pay Scattered Vulnerabilities Across the Web  @HackersOnBoard
Uploaded December 2019 | Updated September 2026, 2 hours ago
The 2016 WWDC saw the dawn of Apple Pay Web, an API that lets websites embed an Apple Pay button within their web-facing stores. Supporting it required a complex request flow, complete with client certificates and a custom session server. This proved detrimental, since Apple failed to caution against important side effects of taking in untrusted URLs. As a result, many new SSRF vulnerabilities entered the world. Worse yet, while they were exploitable and discoverable in similar ways, they were spread across distinct codebases in several programming languages, so could not be patched in any generic way.

Apple is not alone - in the process of gluing the web together, Twilio, Salesforce, and others have all created similarly broad attack surfaces. When companies fail to take an honest, empathetic look at how clients will use a product, they shove along hidden security burdens. Those who integrate with an API have less context than those who create it, so are in a worse position to recognize these risks.

Engineers have been talking about defensive programming for decades, but top companies still have trouble practicing it. In this talk we explore these mistakes with demos of affected software, and introduce a powerful model for finding broad classes of bugs.
DEF CON 27 - Joshua Maddux - API-Induced SSRF How Apple Pay Scattered Vulnerabilities Across the WebDEF CON 27 - The Dark Tangent - Closing CeremoniesOver-the-Air: How we Remotely Compromised the Gateway, BCM, and Autopilot ECUs of Tesla CarsBlack Hat USA 2018 - Outsmarting the Smart CityBlack Hat USA 2018 - Meltdown Basics, Details, ConsequencesBlack Hat USA 2018 - An Attacker Looks at Docker Approaching Multi Container ApplicationsBlack Hat USA 2018 - Every ROSE has its Thorn The Dark Art of Remote Online Social EngineeringDEF CON 27 - albinowax - HTTP Desync Attacks Smashing into the Cell Next DoorDEF CON 27 - Jesse Michael - Get Off the Kernel if You Cant DriveDEF CON 27 - Joe Grand Kingpin - Behind the Scenes of the DEFCON 27 BadgeBlack Hat USA 2018 - A Brief History of Mitigation The Path to EL1 in iOS 11Black Hat USA 2018 - Reconstruct the World from Vanished Shadow Recovering Deleted VSS Snapshots
HackersOnBoard |

DEF CON 27 - Joshua Maddux - API-Induced SSRF How Apple Pay Scattered Vulnerabilities Across the Web

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER