Showing posts with label presentations. Show all posts
Showing posts with label presentations. Show all posts

Monday, January 26, 2026

More Scope Injection for Fun and Profit (or, why those security updates broke your functions)


Introduction 

Like "Big Two-Hearted River," my last post also has a Part II.  I had previously spent countless hours trying to create a UDFMethod object from user-controlled data via the Service Layer endpoints and eventually gave up decided it was just not possible.  But I had learned more about how lots of ColdFusion internals work -- including variable casting, object types, and functions.  And I kept at it.  While I wasn't able to achieve remote code execution, I ultimately did find a few new scope injection vulnerabilities later on.  These vulnerabilities highlight a broader and often overlooked risk: assumptions about scope isolation and variable safety can quietly break down at the framework level. When that happens, even well-intentioned application logic can become vulnerable in unexpected ways.

The corresponding patches for these vulnerabilities introduced breaking changes with the security fixes -- specifically, the requirement to explicitly declare all arguments for remote functions from APSB25-52 and the changes around scope precedence and variable name reserved words from APSB25-105. Read on as we explore the technical details of how they work and what the underlying risks are.

Districton 1 Slides - Control the Variables and You Control the Code: Language-Level Vulnerabilities in Adobe ColdFusion

It was an honor to speak at DistrictCon Year 1 (which is its second year.  Unlike ColdFusion, DistrictCon counts from 0. ðŸ˜€)

I got some great questions and feedback after my talk, attended a bunch interesting sessions, and really enjoyed the weekend.  And yes, there was snow.  Lots and lots of snow.  But the conference team, hotel staff, and attendees all handled the weather incredibly well.  I'm already looking forward to next year, and thinking about potential Junkyard targets...

The slides from my talk -- Control the Variables and You Control the Code: Language-Level Vulnerabilities in Adobe ColdFusion -- are now available online below.  Be sure to check out my longer blog post talking about several of the vulnerabilities covered in my presentation too!

Tuesday, June 24, 2025

CFCamp 2025 Slides - Understanding CFML Vulnerabilities, Exploits, and Attack Paths

 In May I had the pleasure of attending my first CFCamp, where I spoke about CFML security.


The slides from my talk -- Understanding CFML Vulnerabilities, Exploits, and Attack Paths -- are now online below.  With an added bonus of Bavaria in Springtime!

Thursday, August 8, 2024

BSidesLV 2024 Slides - Modern ColdFusion Exploitation and Attack Surface Reduction

Thank you to BSidesLV for the opportunity to speak this year.  The slides from my talk, Modern ColdFusion Exploitation and Attack Surface Reduction, are now online below.  They're pretty similar to my Summercon slides, with a few updates.

Monday, July 22, 2024

Summercon 2024 Slides - Modern ColdFusion Exploitation and Attack Surface Reduction

Last Friday it was an absolute honor to talk about ColdFusion security at Summercon.  Summercon was the first security conference I attended and it remains my favorite after many years, as BlackHat has gotten enormous and other cons have run their course.  The slides from my talk Modern ColdFusion Exploitation and Attack Surface Reduction are below.  This talk is the result of several years of thinking about, examining, and researching the attack surface of ColdFusion from both offensive and defensive perspectives.  I'll also be giving the talk again at BSides Las Vegas next month -- with some updated slides, content, and surprises.

Monday, April 10, 2023

Slides from ColdFusion Summit East 2023 - "Codes, Ciphers, and ColdFusion: What They Don't Want You To Know"

I spoke at ColdFusion Summit East 2023 last week.  I was fortunate to catch some good talks and Springtime in Washington, DC is always a great time to visit.  My talk was on ColdFusion and Encryption -- what to use, what not to use, and how to securely implement encryption into your applications.  I've shared my slides below, and I plan to turn the content into a few forthcoming blog posts.  

Thursday, October 6, 2022

Slides from ColdFusion Summit 2022 - "Below the Surface: Web Vulnerabilities Hiding in your Applications"

Photo credit: @coldfumonkeh

I attended my first CFSummit, where I talked about a handful of web vulnerability classes (SSRF, Session Puzzles, Cryptography flaws, and XML attacks) that might be overlooked by some ColdFusion/CFML developers.  It was a great conference, and I'm looking forward to returning for future events!  My slides are shared below, and I may turn some of the content into forthcoming blog posts.