30 lines
1.1 KiB
Markdown
30 lines
1.1 KiB
Markdown
## CDN
|
|
|
|
db used: sqlite
|
|
flag.txt: GEMASTIK{random sha256 generated on app start}
|
|
|
|
### feature:
|
|
[authentication required with login and register, register default as "user" role]
|
|
1. upload image
|
|
|
|
### Vulns
|
|
#### vuln1: SSTI on image Date Created metadata, exiftool cant insert this, need to write the image's blob
|
|
example:
|
|
```bash
|
|
(base) jons@01-20-jonathanmarbun:/mnt/c/1Jonathan/CTFS/gawe/gms25/web2/exploit$ exiftool -overwrite_original -IPTC:DateCreated="{{7*7}}" image.png
|
|
Warning: Invalid date format (use YYYY:mm:dd) in IPTC:DateCreated (ValueConvInv)
|
|
Nothing to do.
|
|
```
|
|
payload to inject:
|
|
```{{lipsum.__builtins__['open']('flag.txt').read()}}```
|
|
|
|
when editing the Date Created metadata manually, somehow it has limit of 46 char (but we can expand that to make it more by deleting the content of another metadata) -> check ssti.png
|
|
it probably have different behavior on another image file or format
|
|
payload: check exploit/exp3.py
|
|
|
|
#### vuln2:
|
|
|
|
### Patching Rule?
|
|
- dont remove flag.txt/changes its content
|
|
- ensure image metadata generation still available
|
|
- ensure exiftool still used |