<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
    <channel>
        <title>Samuel Erb and Justin Gardner: Crossing the KASM — A Pentest Story</title>
        <link>https://peertube.eqver.se/videos/watch/037885c5-f9f7-4b73-94c9-1b6e99876ea8</link>
        <description>A DEF CON 30 talk about how a seemingly hardened bug bounty target — KASM Workspaces, an enterprise Docker-based VDI solution — was ultimately compromised. At first, the target appeared nearly untouchable: no source code, no obvious vulnerabilities, tightly secured architecture. But after reversing Python binaries, the real hunt began. The speakers walk through the full exploit chain: NGINX configuration injection via the Host header, filter bypass using ISO-8859-1 encoding, SSRF → LFI → extraction of KASM Agent secrets → command execution as root inside Docker and eventual breakout to the host.</description>
        <lastBuildDate>Fri, 24 Jul 2026 11:35:47 GMT</lastBuildDate>
        <docs>https://validator.w3.org/feed/docs/rss2.html</docs>
        <generator>PeerTube - https://peertube.eqver.se</generator>
        <image>
            <title>Samuel Erb and Justin Gardner: Crossing the KASM — A Pentest Story</title>
            <url>https://peertube.eqver.se/client/assets/images/icons/icon-512x512.png</url>
            <link>https://peertube.eqver.se/videos/watch/037885c5-f9f7-4b73-94c9-1b6e99876ea8</link>
        </image>
        <copyright>All rights reserved, unless otherwise specified in the terms specified at https://peertube.eqver.se/about and potential licenses granted by each content's rightholder.</copyright>
        <atom:link href="https://peertube.eqver.se/feeds/video-comments.xml?videoId=037885c5-f9f7-4b73-94c9-1b6e99876ea8" rel="self" type="application/rss+xml"/>
    </channel>
</rss>