Перейти к содержимому

Request Smuggling & SSRF = Flag? - HTB Proxy - Hack The Box Business CTF

PinkDraconian

0:00 / 0:00

Request Smuggling & SSRF = Flag? - HTB Proxy - Hack The Box Business CTF

3 743 просмотра · 2 года назад
PinkDraconian
19,6 тыс. подписчиков
3 743 просмотра · 2 года назад
This video was sponsored by Hack The Box. Visit their website to learn more about their awesome cybersecurity lab offerings: https://affiliate.hackthebox.com/azng... ▶️ YouTube:    / pinkdraconian   🎁 Patreon:   / pinkdraconian   🐦 Twitter:   / pinkdraconian   🎵 TikTok:   / pinkdraconian   ℹ️ LinkedIn:   / robbe-van-roey-365666195   📞 Discord: PinkDraconian#9907 📷 Instagram:   / robbevanroey   🕸️ Website: http://pinkdraconian.d4rkc0de.com/ 👨‍💻 HackTheBox: https://www.hackthebox.eu/home/users/... 🤖 Reddit:   / pinkdraconian   ☁️ Steam: https://steamcommunity.com/id/PinkDra... 🐈 GitHub: https://github.com/PinkDraconian Timestamps: 00:00 Introduction 00:51 Checking out the challenge 04:16 Figuring out the end goal for solving the challenge 05:20 Digging into a potential OS command injection 07:15 Looking at the requests to the proxy in Caido 08:00 Bypassing localhost checks 15:50 HTTP Request Smuggling 20:16 Solving the challenge by chaining the SSRF, HTTP Request Smuggling and OS command injection