miscProhard

nix-revenge

kalmarctf

Task: source and VM exposed a web panel that accepted arbitrary Nix expressions and a root rebuild helper using VERSION_SUFFIX. Solution: poison the pinned Nix source fixed-output derivation with Linux fd smuggling, then let root rebuild Nix from the corrupted store path and leak the copied flag.

$ ls tags/ techniques/
fod_corruptionscm_rights_fd_smugglingsource_tree_poisoningprivileged_rebuild_poisoning

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Sign in with GitHub to continue. No email required.

$sign in

$ grep --similar

Similar writeups