Cookie Forgery, Signature Bypass and Blind Command Injection - "Feature Unlocked" [CSCTF 2024]
Автор: CryptoCat
Загружено: 2024-09-01
Просмотров: 1698
Описание:
Video walkthrough for the "Feature Unlocked" web challenge I made for CyberSpace CTF 2024. The challenge required players to hijack the validation server via a hidden GET parameter, cookie forgery and custom signature generation/verification in order to access an unreleased feature, which itself contained a blind command injection vulnerability. Hope you enjoy 🙂 #CSCTF #CTF #CaptureTheFlag #Pentesting #OffSec #WebSec #AppSec
Write-up: https://cryptocat.me/blog/ctf/2024/cy...
↢CyberSpace CTF 2024↣
https://2024.csc.tf
https://ctftime.org/event/2428
https://discord.csc.tf
👷♂️Resources🛠
https://cryptocat.me/resources
↢Chapters↣
0:00 Start
1:46 Source code review
2:33 Cookie forgery
4:13 Recreate validation server
6:20 Access unlocked feature
7:27 Command injection
8:16 Blind exfiltration
10:01 End
Повторяем попытку...
Доступные форматы для скачивания:
Скачать видео
-
Информация по загрузке: