webProhard
Ecler 2
spbctf
Task: Flask image hosting service with ImageMagick processing and internal Docker service. Solution: MVG injection via unsanitized username to achieve RCE through pipe delegate, bypassing network restrictions with Python urllib to SSRF internal service.
$ ls tags/ techniques/
mvg_injectionimagemagick_pipe_delegatessrf_to_internal_servicerestricted_user_bypassbase64_payload_encoding
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Sign in with GitHub to continue. No email required.
$sign in$ grep --similar
Similar writeups
- [web][Pro]Photo Storage— miptctf
- [web][Pro]Print on Demand (Печать по запросу)— duckerz
- [web][Pro]Bad Apple— tamuctf
- [web][Pro]After Image— srdnlen
- [misc][Pro]Иерархия (Hierarchy)— duckerz