15 lines
600 B
Markdown
15 lines
600 B
Markdown
## Blogpost
|
|
|
|
db used: sqlite
|
|
flag.txt: GEMASTIK{random sha256 generated on app start}
|
|
|
|
feature:
|
|
[authentication required with login and register, register default as "user" role]
|
|
1. search feature
|
|
2. create, edit, visit post form that can upload images (png, jpg/jpeg, bmp) query the image metadata taken with exiftool to the sqlite database
|
|
3. profile (if the account type is admin, render the content of flag.txt)
|
|
|
|
vuln1: Command injection on exiftool (payload: exp1.py)
|
|
vuln2: SQLi on image metadata to enable altering user account into admin account (payload: sqli.png, exp2.py)
|
|
|
|
patching rules?: |