<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Host Header Injection on Saksham Anand</title>
    <link>/tags/host-header-injection/</link>
    <description>Recent content in Host Header Injection on Saksham Anand</description>
    <generator>Hugo -- gohugo.io</generator>
    <language>en-us</language>
    <lastBuildDate>Mon, 25 May 2020 00:00:00 +0000</lastBuildDate>
    <atom:link href="/tags/host-header-injection/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>CVE-2020-26163 BigBlueButton | Host Header Injection</title>
      <link>/blog/host-header-injection-bigbluebutton/</link>
      <pubDate>Mon, 25 May 2020 00:00:00 +0000</pubDate>
      <guid>/blog/host-header-injection-bigbluebutton/</guid>
      <description>Back in April, one of the systems I was testing was a video conferencing application, known as BigBlueButton, an open source challenger to Zoom.
The BigBlueButton installation comes with a user friendly interface, known as Greenlight, which ties in nicely with the BigBlueButton server. While most of the corporate installations would be using LDAP authentication, at times, installation will be based on standard username and password login mechanism, which is handled by Greenlight.</description>
    </item>
  </channel>
</rss>
