Exploiting Java Tomcat With a Crazy JSP Web Shell - Real World CTF 2022

LiveOverflow
LiveOverflow
89.2 هزار بار بازدید - 2 سال پیش - This was a hard web
This was a hard web CTF challenge involving a JSP file upload with very restricted character sets. We had to use the Expression Language (EL) to construct useful primitives and upload an ascii-only .jar file.

Alternative writeups: https://github.com/voidfyoo/rwctf-4th...
Fuzzing log4j with Jazzer: Fuzzing Java to Find Log4j Vulnerabil...

=[ ❤️ Support ]=

→ per Video: Patreon: liveoverflow
→ per Month: @liveoverflow

=[ 🐕 Social ]=

→ Twitter: Twitter: LiveOverflow
→ Instagram: Instagram: LiveOverflow
→ Blog: https://liveoverflow.com/
→ Subreddit: Reddit: LiveOverflow
→ Facebook: Facebook: LiveOverflow
2 سال پیش در تاریخ 1400/12/05 منتشر شده است.
89,230 بـار بازدید شده
... بیشتر