DEF CON 27 - Michael Stepankin - Apache Solr Injection @HackersOnBoard
DEF CON 27 - Michael Stepankin - Apache Solr Injection  @HackersOnBoard
Uploaded December 2019 | Updated September 2026, 10 hours ago
Apache Solr is a search platform used by many enterprise companies to add a full text search functionality to their websites. Often hidden behind firewalls, it provides a rich API to search across large datasets. If this API is used by web applications in a wrong way, it may open a possibility for injection attacks to completely modify the query logic.

In this talk we’ll shed some light on the new type of vulnerabilities for web applications - Solr parameter injection, and provide some useful ways how to achieve remote code execution through it. We also provide exploits for almost all known vulnerabilities for Apache Solr, including the two new RCEs we reported this year.
DEF CON 27 - Michael Stepankin - Apache Solr InjectionBlack Hat USA 2018 Mental Health Hacks Fighting Burnout, Depression and Suicide in the Hacker CommunDEF CON 27 - Mike Spicer - I Know What You Did Last Summer 3 Years of Wireless Monitoring at DEF CONDEF CON 27 - Andreas Baumhof - Are Quantum Computers Really A Threat To CryptographyDEF CON 27 - Ben Sadeghipour - Owning The Clout Through Server-Side Request ForgeryDEF CON 27 - Junyu Zhou - Web2Own Attacking Desktop Apps From Web Securitys PerspectiveDEF CON 27 - Marina Simakov - Relaying Credentials Has Never Been EasierDEF CON 27 - Omer Gull - SELECT code execution FROM USING SQLiteDEF CON 27 - Xiaolong Bai - HackPac Hacking Pointer Authentication in iOS User SpaceDEF CON 27 - Itzik Kotler - Process Injection Techniques Gotta Catch Them AllBlack Hat USA 2018 - Deep Dive into an ICS Firewall, Looking for the Fire HoleDEF CON 27 - Can You Track Me Now? Why The Phone Companies Are Such A Privacy Disaster
HackersOnBoard |

DEF CON 27 - Michael Stepankin - Apache Solr Injection

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER