SEC-T 0x10: Orange Tsai - Confusion Attacks: Exploiting Hidden Semantic Ambiguity in Apache

Orange Tsai - Confusion Attacks: Exploiting Hidden Semantic Ambiguity in Apache HTTP Server! A talk by Orange Tsai The Apache HTTP Server is comprised of dozens of different modules, which are coupled together. While delving into the source by chance, we discovered that the coding style seemed a little bit... open? When a new HTTP request arrives, all modules uphold and maintain a colossal structure, collaborating in harmony to complete the request. While this cooperation might sound ideal, the reality reveals a significant challenge: the modules are not entirely familiar with each other, especially regarding the implementation details. However, they are asked to collaborate to fulfill the task. If any module has an incorrect understanding of any fields of this huge structure, it could potentially lead to fatal issues. This observation led us to focus on interactions between modules, and discover this new attack surface. Let's see how a seemingly harmless structure modification can be passed through layers, amplifying the impact and affecting other modules to become vulnerabilities. This novel attack surface unearthed 3 distinct types of Confusion Attacks and 8 vulnerabilities, which allow us to navigate easily between Httpd modules, generating various attacks based on the different functionalities of modules: from the simplest arbitrary source code disclosure to bypassing ACL, and enabling unlimited SSRF. Of course, we won't forget about RCE, we will demonstrate how a long-underestimated bug type can be transformed into code execution by leveraging Httpd's internal features! About the Speaker Orange Tsai, is the principal security researcher of DEVCORE and the core member of CHROOT security group in Taiwan. He is the champion and the "Master of Pwn" title holder at Pwn2Own Vancouver 2021 and Toronto 2022. Currently, Orange is a 0day researcher focusing on Web and Application Security. His research not only earned him the Pwnie Awards winner for "Best Server-Side Bug" in 2019 and 2021 but also secured 1st place in the "Top 10 Web Hacking Techniques" for 2017 and 2018.

SEC-T 0x10: Or Yair - MagicDot: A Hacker's Magic Show of Disappearing Dots and Spaces
▶︎

SEC-T 0x10: Or Yair - MagicDot: A Hacker's Magic Show of Disappearing Dots and Spaces

Zig 2026: No-AI Policy, $670K Foundation, Left GitHub & Why Zig Isn’t 1.0 - Andrew Kelley Explains
▶︎

Zig 2026: No-AI Policy, $670K Foundation, Left GitHub & Why Zig Isn’t 1.0 - Andrew Kelley Explains

How to solve a Python mystery
▶︎

How to solve a Python mystery

Confusion Attacks: Exploiting Hidden Semantic Ambiguity In Apache HTTP Server! - Orange Tsai
▶︎

Confusion Attacks: Exploiting Hidden Semantic Ambiguity In Apache HTTP Server! - Orange Tsai

SEC-T 0x10: David El - Behind the Cheats: A Tale About the Greedy Cheat Developer
▶︎

SEC-T 0x10: David El - Behind the Cheats: A Tale About the Greedy Cheat Developer

The C Killer? I Tried Odin Lang
▶︎

The C Killer? I Tried Odin Lang

Keynote: After the AI Hype – What’s Real, and What’s Next - Richard Campbell - 2026
▶︎

Keynote: After the AI Hype – What’s Real, and What’s Next - Richard Campbell - 2026

I Hacked This Temu Router. What I Found Should Be Illegal.
▶︎

I Hacked This Temu Router. What I Found Should Be Illegal.

Something is jamming GPS over Europe. Here's what we found
▶︎

Something is jamming GPS over Europe. Here's what we found

How To Think SO CLEARLY People Assume You're A Genius
▶︎

How To Think SO CLEARLY People Assume You're A Genius

How Google Translate Exposed Russia's Secret Army
▶︎

How Google Translate Exposed Russia's Secret Army

Creator of C++: Bell Labs, Negative Overhead Abstraction, Mistakes | Bjarne Stroustrup
▶︎

Creator of C++: Bell Labs, Negative Overhead Abstraction, Mistakes | Bjarne Stroustrup

Attacking AI - Jason Haddix - NDC Security 2026
▶︎

Attacking AI - Jason Haddix - NDC Security 2026

God Says:"TAKE THIS MESSAGE SERIOUSLY, BECAUSE ONLY YOU ARE SEEING IT"/God Message Now/God Message
▶︎

God Says:"TAKE THIS MESSAGE SERIOUSLY, BECAUSE ONLY YOU ARE SEEING IT"/God Message Now/God Message

What Is PID Control? | Understanding PID Control, Part 1
▶︎

What Is PID Control? | Understanding PID Control, Part 1

Confusion Attacks: Exploiting Hidden Semantic Ambiguity in Apache HTTP Server!
▶︎

Confusion Attacks: Exploiting Hidden Semantic Ambiguity in Apache HTTP Server!

Trump Sends Vance to Concede to Iran & Reflecting Pool Is Filled with Corruption | The Daily Show
▶︎

Trump Sends Vance to Concede to Iran & Reflecting Pool Is Filled with Corruption | The Daily Show

Inside Dyson’s Overengineered £1000 Hand Dryer
▶︎

Inside Dyson’s Overengineered £1000 Hand Dryer

How to Hide in Plain Sight: Next-Level Digital Privacy | Ivan Banov at BSidesCache 2025
▶︎

How to Hide in Plain Sight: Next-Level Digital Privacy | Ivan Banov at BSidesCache 2025

Putin breaks silence over Moscow strikes humiliation | Russia-Ukraine latest war news
▶︎

Putin breaks silence over Moscow strikes humiliation | Russia-Ukraine latest war news