webPromedium
Print on Demand (Печать по запросу)
duckerz
Task: Flask web app generating PDF certificates from user-supplied XML with an internal API holding the flag. Solution: Exploited XXE via insecure lxml parser (no_network=False, resolve_entities=True) to SSRF the internal Docker service, exfiltrating the admin UUID and flag through the generated PDF.
$ ls tags/ techniques/
xxe_to_ssrfdocker_service_discoveryxml_entity_injection
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Sign in with GitHub to continue. No email required.
$sign in$ grep --similar
Similar writeups
- [web][Pro]UUIDY— duckerz
- [misc][Pro]Иерархия (Hierarchy)— duckerz
- [web][Pro]Арифметика (Arithmetic)— duckerz
- [web][Pro]Ecler 2— spbctf
- [web][Pro]110 - Retro Search (Ретро поиск) - duckerz CTF— duckerz