Finding 0day in Apache APISIX During CTF (CVE-2022-24112) @LiveOverflow
Finding 0day in Apache APISIX During CTF (CVE-2022-24112)  @LiveOverflow
Uploaded March 2022 | Updated September 2026, 2 weeks ago
This code audit of the API6 challenge from Real World CTF investigates Apache APISIX and discovers how a default configuration can be escalated to remote code execution. The exploit uses the batch-requests plugin for server-side request forgery (SSRF), bypasses an X-Real-IP restriction, and became CVE-2022-24112.

LEARN ON HEXTREE (ad)
Learn hacking on Hextree: hextree.io
Watch this video and more on Hextree: app.hextree.io/courses/yt-0day/web-security
Join the Hextree Discord: discord.gg/xgQpCQCpvy

RESOURCES
CVE-2022-24112: seclists.org/oss-sec/2022/q1/133
GitLab Real World CTF write-up: liveoverflow.com/gitlab-11-4-7-remote-code-execution-real-world-ctf-2018
Challenge files: github.com/chaitin/Real-World-CTF-4th-Challenge-Attachments/tree/master/API6

CHAPTERS
00:00 - Intro
01:09 - Initial Application Overview
02:15 - Discussing Approaches
03:56 - Reading Documentation
04:57 - Initial Attack Idea
06:15 - Identifying Attack Surface
08:46 - Discovering Batch Requests
09:18 - Bypassing X-Real-IP Header
10:15 - Testing the Exploit
11:11 - Reporting the Issue
12:16 - Outro

SUPPORT
Per video: patreon.com/join/liveoverflow
Per month: youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w/join
Buy my handwriting font (ad): shop.liveoverflow.com

WATCH, FOLLOW & READ
Second channel: youtube.com/LiveUnderflow
Twitch: twitch.tv/LiveOverflow
Twitter: twitter.com/LiveOverflow
Instagram: instagram.com/LiveOverflow
TikTok: tiktok.com/@liveoverflow_
LiveOverflow blog: liveoverflow.com
Hextree blog (ad): hextree.io/blog

#WebSecurity #CTF #LiveOverflow

(ad) LiveOverflow YouTube channel is supported by advertisement and product placement.
Finding 0day in Apache APISIX During CTF (CVE-2022-24112)My Life in Short/Shirt Stories - The Time I Learned PenSpinning (~2007-2009) - Shirt Stories #1Hacking My Instagram AccountUnderstanding C Pointer Magic Arithmetic | Ep. 07
LiveOverflow |

Finding 0day in Apache APISIX During CTF (CVE-2022-24112)

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER