Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

SSRF vs Business Critical Applications

Black Hat via YouTube

Overview

Limited-Time Offer: Up to 75% Off Coursera Plus!
7000+ certificate courses from Google, Microsoft, IBM, and many more.
This course focuses on teaching learners how to exploit Server Side Request Forgery (SSRF) vulnerabilities in business critical applications, with a specific emphasis on SAP systems. The course covers the history and types of SSRF attacks, as well as the use of XXE Tunneling to bypass security restrictions and execute attacks. Participants will learn how to identify SSRF vulnerabilities, conduct remote SSRF attacks, and bypass security measures in SAP systems. The teaching method includes theoretical explanations, practical examples, and demonstrations. This course is intended for cybersecurity professionals, penetration testers, and individuals interested in understanding and mitigating SSRF vulnerabilities in enterprise applications.

Syllabus

Intro
2 ERP Scan
Enterprise applications: Definitions
Business-critical systems architecture
Secure corporate network
Corporate network attack scenario
SSRF History: Basics
SSRF history: World research
Trusted SSRF: Oracle Database
SSRF Types: SAP
Remote SSRF: Subtypes
Simple Remote SSRF: Login bruteforce
XXE Attacks on other services
Full Remote SSRF
Remote SSRF threats
XXE Tunneling to Verb Tampering
XXE Tunneling to Buffer Overflow (Hint 2)
XXE Tunneling to Buffer Overflow: Packet B
XXE Tunneling to Buffer Overflow (Hint 3)
XXE Tunneling to Rsh
Bypass SAP security restrictions
SAP Gateway server security bypass: Exploit
SAP Message Server security bypass
Oracle DB security bypass
Conclusion?
Purpose
How is it working?
Few steps
Action: Test
Action: Scan
Action: Attack
DEMO

Taught by

Black Hat

Reviews

Start your review of SSRF vs Business Critical Applications

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.