Loading video...
Video Failed to Load
Real-world scenario [10]: (RCE via Cart) #CTF #bugbounty #bugbountytips #bugbountytip
18,778 views • 8 days ago •via X (Twitter)
9 Comments

this is so cool , but intrested to know if this ctf is build on real world scenario ?

Sure with the same specifications and standards it was there and Bounty paid $ 2050

To clarify, the scenario before the RCE is a Deserialization vulnerability The main idea is that the website restores a stored variable like light/dark mode During this restoration process in memory a malicious payload manipulates the backend Magic Methods triggering RCE

Any tech details on it how do you get that there is also file parameter which was accepting and so on.

Dm

Any write-up?

ما تنزلهم يوتيوب

دي بلات فورم بتجهز لسه يا كوتش كلها سينريوهات real world وفيها تيم مصري هندي ..هتجهز قريب إن شاء الله

شكراً يا معلم وربي أساطير
