Exploiting a File Upload Vulnerability - MetaCTF

Поділитися
Вставка
  • Опубліковано 23 сер 2024
  • Follow me - beacons.page/shenetworks
    This challenge was apart of a Black Hills Information Security miniCTF
    Cyber Range - www.antisyphon...
    BHIS Twitter - / bhinfosecurity
    Backdoor - gist.github.co...

КОМЕНТАРІ • 31

  • @franklinstevens3540
    @franklinstevens3540 Рік тому +5

    I really enjoyed this. The break down was top-notch and easy to follow. Thanks.

  • @simonwatson5299
    @simonwatson5299 Рік тому +1

    The last time I heard what sounded like 'rubber keys' was on my Sinclair 48K back in the 1980's, lol. If you've bought a keyboard with rubber keys, junk it. Lifes too short. Anyway, great video as always. And thanks for the FREE education, it's very much appreciated. Can't wait till next vid. 😚

  • @nichetcher1
    @nichetcher1 8 місяців тому

    So awesome to learn by watching you do this Ctf.

  • @poxishovel
    @poxishovel Рік тому +1

    Love the video! Thanks for sharing your knowledge.

  • @Liquid6t9
    @Liquid6t9 Рік тому +1

    Excellent content! Keep it up.

  • @ForeverMan
    @ForeverMan 5 місяців тому +1

    well, this exploit is IMPOSSIBLE... I have no idea how that server parsed a PNG as PHP, that might be part of the CTF but in real world, its impossible

    • @tiptrcks3960
      @tiptrcks3960 5 місяців тому

      Hey dude do you have any idea if the server converts the image to base64 and then appends it in src of img tag instead of relying on image path, then is there any way to go further?

  • @8080VB
    @8080VB 23 дні тому

    Hey I just tried in a local php server to see if it works. Unfortunately it doesn't. I saw this method last day tried adding in multiple paths in an image. Still doesn't. This won't work in a Apache server or a php?

  • @dazztee
    @dazztee Рік тому

    kool enjoyed, look forward to some more

  • @user-pk3pl3qg7b
    @user-pk3pl3qg7b Рік тому +1

    how to learn find vulnerability ?

  • @kazhiroma9736
    @kazhiroma9736 5 місяців тому

    currently very similar challenge in picoCTF

  • @GamingTy12
    @GamingTy12 Рік тому

    holy videos LETS GOOOOOOOOOOOOOO!

  • @Ankitverma-yc7zf
    @Ankitverma-yc7zf 3 місяці тому

    When I tried this on my local machine with apache web server, my server is not returning the image data as shown in your video instead of that my server is rendering the image. I dont understand that how in your browser the image is not rendering and server is giving the image data as text.

  • @RMD80GAMER
    @RMD80GAMER Рік тому

    Thank you for your hard work 😄

  • @dafoxlana
    @dafoxlana 5 місяців тому

    Thank you !! :)

  • @user-bh3vo2dl9z
    @user-bh3vo2dl9z 8 місяців тому

    what if there is permission, that outputting "Acess denied" in page?

  • @steiner254
    @steiner254 Рік тому

    Awesome!

  • @lazyguy9977
    @lazyguy9977 Рік тому

    Good stuff

  • @diwi_dw
    @diwi_dw Рік тому

    👍👍

  • @linuxturtorials9591
    @linuxturtorials9591 9 місяців тому +2

    Assalam aleykum every man an and women must cover their bodies according to islam

  • @viniciusnascimento4285
    @viniciusnascimento4285 8 місяців тому +1

    lol woman

  • @liamtwine2267
    @liamtwine2267 Рік тому

    Omg. Your the most beautiful hacker I have ever seen. As a fellow pentester I see many people on a daily basis but you are incredible.

    • @LushRuins
      @LushRuins 11 місяців тому

      simp

    • @Flaneur27
      @Flaneur27 8 місяців тому +1

      Lmfaoo you can’t be serious Lmfaoo not the place to shoot your shot

  • @anuradhalakruwan1918
    @anuradhalakruwan1918 Рік тому

    Friend I like learning Cybersecurity..... Please help me friend...?

  • @cakesnatcher4541
    @cakesnatcher4541 10 місяців тому +1

    U can exploit Hadjis file anyday

  • @aminmgs9932
    @aminmgs9932 Рік тому

    contains a virus so the upload was canceled: YARA.php_in_image.UNOFFICIAL FOUND pls help