Target from: CTF Playground

Intermediate, Non rootable, Timed

inject / 0.0.0.0

3: Flags (2:app, env)
1: Service
1,310 pts
Avg. headshot: 372 minutes

#headshot

Level 6 / Securitas

novena / 392nd Place

3: Flags found
1: Service discovered
1,310 pts
25 minutes

Everyone speaks about escaping user input to avoid injections but if you are a developer trying to actually implement a protection like this you are on your own.

The developer of this application, had all the good intentions, he even used some suggested solutions from stackoverflow.com... and we all know how well that usually goes.

To start the challenge connect with nc 10.0.14.25 1337. Your timer starts from the first time you connect to the service.

Activity Stream

Latest activity on the platform

novena managed to headshot [inject], in 25 minutes, 28 months ago
novena Got the env flag of inject for 500 points, 28 months ago
novena Got the flag of inject for 500 points, 28 months ago
novena Got the flag of inject for 300 points, 28 months ago
novena Is getting started with inject for 10 points, 28 months ago