$ cat writeup.md…
$ cat writeup.md…
hackadvisor
Task: Media storage platform with server-side ExifTool metadata stripping on uploaded images, plus URL import feature. Solution: exploit CVE-2021-22204 (ExifTool DjVu Perl code injection) via malicious JPEG with embedded DjVu payload in HasselbladExif tag, confirm blind RCE with sleep timing, then exfiltrate flag via SSRF using file:// protocol in the URL import endpoint.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar