Target from: CTF Playground

Intermediate, Non rootable, Timed

inject / 0.0.0.0

3: Flags (2:app, env)
1: Service
1,310 pts
Avg. headshot: 372 minutes

50%

Level 6 / Securitas

othmanesp / 363rd Place

1: Flags found
1: Service discovered
310 pts

Everyone speaks about escaping user input to avoid injections but if you are a developer trying to actually implement a protection like this you are on your own.

The developer of this application, had all the good intentions, he even used some suggested solutions from stackoverflow.com... and we all know how well that usually goes.

To start the challenge connect with nc 10.0.14.25 1337. Your timer starts from the first time you connect to the service.

Activity Stream

Latest activity on the platform

othmanesp Got the flag of inject for 300 points, 28 months ago
othmanesp Is getting started with inject for 10 points, 28 months ago