Loading video...

Video Failed to Load

Go Home

Real-world scenario [10]: (RCE via Cart) #CTF #bugbounty #bugbountytips #bugbountytip

18,778 views • 8 days ago •via X (Twitter)

9 Comments

zack0x01's profile picture
zack0x017 days ago

this is so cool , but intrested to know if this ctf is build on real world scenario ?

𝗗𝘀𝗼𝗸𝗲𝗩🧑‍💻's profile picture
𝗗𝘀𝗼𝗸𝗲𝗩🧑‍💻7 days ago

Sure with the same specifications and standards it was there and Bounty paid $ 2050

im Nhyy's profile picture
im Nhyy7 days ago

To clarify, the scenario before the RCE is a Deserialization vulnerability The main idea is that the website restores a stored variable like light/dark mode During this restoration process in memory a malicious payload manipulates the backend Magic Methods triggering RCE

Piyush Khosla's profile picture
Piyush Khosla7 days ago

Any tech details on it how do you get that there is also file parameter which was accepting and so on.

𝗗𝘀𝗼𝗸𝗲𝗩🧑‍💻's profile picture
𝗗𝘀𝗼𝗸𝗲𝗩🧑‍💻7 days ago

Dm

chwrld's profile picture
chwrld6 days ago

Any write-up?

Younis Jabr's profile picture
Younis Jabr6 days ago

ما تنزلهم يوتيوب

𝗗𝘀𝗼𝗸𝗲𝗩🧑‍💻's profile picture
𝗗𝘀𝗼𝗸𝗲𝗩🧑‍💻6 days ago

دي بلات فورم بتجهز لسه يا كوتش كلها سينريوهات real world وفيها تيم مصري هندي ..هتجهز قريب إن شاء الله

Younis Jabr's profile picture
Younis Jabr6 days ago

شكراً يا معلم وربي أساطير

Related Videos