webProhard

Ecler 2

spbctf

Task: Flask image hosting service with ImageMagick processing and internal Docker service. Solution: MVG injection via unsanitized username to achieve RCE through pipe delegate, bypassing network restrictions with Python urllib to SSRF internal service.

$ ls tags/ techniques/
mvg_injectionimagemagick_pipe_delegatessrf_to_internal_servicerestricted_user_bypassbase64_payload_encoding

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Sign in with GitHub to continue. No email required.

$sign in

$ grep --similar

Similar writeups