DEF CON 33 - Client or Server? Hidden Sword of Damocles in Kafka - Ji'an Zhou, Ying Zhu, ZiYang ' Li

DEF CON 33 - Client or Server? Hidden Sword of Damocles in Kafka - Ji'an Zhou, Ying Zhu, ZiYang ' Li

Source: YouTube · DEFCONConference · published Oct 10, 2025 · 34:08

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

Revised Summary (Optimized for Clarity, Accuracy, and Impact):

BLUF: A critical remote code execution (RCE) vulnerability was discovered in Apache Kafka, including in its broker and client components—marking the first-ever RCE vulnerability in the Kafka broker. The attack leveraged dynamic configuration bypasses, including LDAP/JMD injection and SASL/GSSAPI-triggered GS process exploitation, enabling full remote takeover. The vulnerability was patched in Kafka 3.4.0 (CVE-2023-25194), but the fix inadvertently impacted both client and broker sides due to shared code logic. A persistent RCE path remains in patched versions via a dynamic callback handler bypass. This discovery led to a record-breaking bug bounty from Confluent and earned recognition as a landmark achievement in Apache Kafka security.

Key Takeaways:

🔹 Remote Code Execution in Kafka Clients via JMD Injection & Poly Login Module Bypass

  • Attackers exploit a controlled connection stream to trigger JMD (Java Naming and Directory Interface) injection in Kafka clients.
  • The client uses a configurable login module, which can be manipulated to invoke a malicious JMD server.
  • A backlist mechanism was introduced in version 3.4.1 to disable dangerous modules (e.g., JMD login), but this was bypassed using the Poly Login Module, which delegates authentication to another module (e.g., JMD) even if it’s on the backlist.
  • This enables a full RCE chain through controlled login configuration and JMD injection.
    Source: 8:32–9:34

🔹 Exploitation of LDAP Login Module via Custom Callback Handler

  • The built-in LDAP login module in JDK (used in Confluent Server) retrieves user credentials via a callback handler.
  • A malicious callback handler—FileBasedDynamicCallbackHandler—was found in Confluent Server (v7.7.1), which reads usernames and passwords from local

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

Hello everyone, thanks for coming. I am very honored to be here to give a presentation. So today our topic is found observant the shan s of democracy in Kafka. First of all let me introduce my team. We are security engineers from Alibaba cloud and I'm Zangi. Then let me introduce the agenda. First I will introduce something about Kafka. Then we compare previous research with our new findings. Next discuss the journey of hunting bus in Kafka ecologic. After that we will uncover the sham abilities in Kafka broker and finally explore the inspe and differences. Okay let's officially begin our presentation. So what's Kafka? According to the official documentation, Apachi Kafka is an open-source distributed event streaming platform widely adapted by the enterprises for building high performance …