Target from: CTF Playground

Intermediate, Non rootable, Timed

inject / 0.0.0.0

3: Flags (2:app, env)
1: Service
1,310 pts
Avg. headshot: 329 minutes

#headshot

Level 4 / User

akdangerous / 551st Place

3: Flags found
1: Service discovered
1,310 pts
46 minutes

Everyone speaks about escaping user input to avoid injections but if you are a developer trying to actually implement a protection like this you are on your own.

The developer of this application, had all the good intentions, he even used some suggested solutions from stackoverflow.com... and we all know how well that usually goes.

To start the challenge connect with nc 10.0.14.25 1337. Your timer starts from the first time you connect to the service.

Activity Stream

Latest activity on the platform

akdangerous managed to headshot [inject], in 46 minutes, 2 days ago
akdangerous Got the env flag of inject for 500 points, 2 days ago
akdangerous Got the flag of inject for 500 points, 2 days ago
akdangerous Got the flag of inject for 300 points, 2 days ago
akdangerous Is getting started with inject for 10 points, 2 days ago