webhard

Ecler 2

spbctf

Task: Flask image hosting service with ImageMagick processing and internal Docker service. Solution: MVG injection via unsanitized username to achieve RCE through pipe delegate, bypassing network restrictions with Python urllib to SSRF internal service.

$ ls tags/ techniques/
mvg_injectionimagemagick_pipe_delegatessrf_to_internal_servicerestricted_user_bypassbase64_payload_encoding

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Create a free account with GitHub, then upgrade to Pro.

$ssh [email protected]