Nginx 1.13.2 configured as a caching reverse proxy, vulnerable to CVE-2017-7529: an integer overflow in the range filter lets a Range header with a negative start return bytes before the cached body, leaking the cache file header (cache key, upstream response headers).
Pas commencéDockercommit 92f78d2x86_64 · aarch64Secret
Exploit CVE-2017-7529 to read the Nginx cache file header and recover what it leaks.
Le brief de ce lab se trouve dans son dépôt.