webmedium

Print on Demand (Печать по запросу)

duckerz

Task: Flask web app generating PDF certificates from user-supplied XML with an internal API holding the flag. Solution: Exploited XXE via insecure lxml parser (no_network=False, resolve_entities=True) to SSRF the internal Docker service, exfiltrating the admin UUID and flag through the generated PDF.

$ ls tags/ techniques/
xxe_to_ssrfdocker_service_discoveryxml_entity_injection

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Create a free account with GitHub, then upgrade to Pro.

$ssh [email protected]