'unfinished' - web - DiceCTF 2023 Challenge Writeup (middleware bypass + mongodb ssrf leak)

preview_player
Показать описание
CTF Writeup for DiceCTF 2023 web/unfinished.
Solution:
1. Bypass login check due to missing return

00:00 Intro
00:52 Other Writeups
01:20 Code Overview
7:54 Search for privesc
13:53 Generate MongoDB wire protocol buffer
18:05 Solve Script
26:23 Conclusion
Рекомендации по теме
visit shbcf.ru