正在加载视频...

视频加载失败

Real-world scenario [10]: (RCE via Cart) #CTF #bugbounty #bugbountytips #bugbountytip

18,778 次观看 • 8 天前 •via X (Twitter)

9 条评论

zack0x01 的头像
zack0x017 天前

this is so cool , but intrested to know if this ctf is build on real world scenario ?

𝗗𝘀𝗼𝗸𝗲𝗩🧑‍💻 的头像
𝗗𝘀𝗼𝗸𝗲𝗩🧑‍💻7 天前

Sure with the same specifications and standards it was there and Bounty paid $ 2050

im Nhyy 的头像
im Nhyy7 天前

To clarify, the scenario before the RCE is a Deserialization vulnerability The main idea is that the website restores a stored variable like light/dark mode During this restoration process in memory a malicious payload manipulates the backend Magic Methods triggering RCE

Piyush Khosla 的头像
Piyush Khosla7 天前

Any tech details on it how do you get that there is also file parameter which was accepting and so on.

𝗗𝘀𝗼𝗸𝗲𝗩🧑‍💻 的头像
𝗗𝘀𝗼𝗸𝗲𝗩🧑‍💻7 天前

Dm

chwrld 的头像
chwrld6 天前

Any write-up?

Younis Jabr 的头像
Younis Jabr7 天前

ما تنزلهم يوتيوب

𝗗𝘀𝗼𝗸𝗲𝗩🧑‍💻 的头像
𝗗𝘀𝗼𝗸𝗲𝗩🧑‍💻7 天前

دي بلات فورم بتجهز لسه يا كوتش كلها سينريوهات real world وفيها تيم مصري هندي ..هتجهز قريب إن شاء الله

Younis Jabr 的头像
Younis Jabr7 天前

شكراً يا معلم وربي أساطير

相关视频