Writeups
-
Easy
Blind OS command injection with out-of-band data exfiltration
fully blind os command injection taken from confirmation to theft, wrapping whoami in backticks so command substitution splices the username into the hostname of a dns lookup that burp collaborator logs
OS command injection 2 min -
Easy
Blind OS command injection with out-of-band interaction
fully blind os command injection with no readable output, no timing and no writable folder, confirmed by injecting nslookup so the server fires a dns lookup to a burp collaborator subdomain
OS command injection 2 min -
Easy
Blind OS command injection with output redirection
blind os command injection where the output is read back by redirecting whoami with > into the writable /var/www/images/ folder and then fetching that file through the image loader
OS command injection 2 min -
Easy
Blind OS command injection with time delays
blind os command injection in a feedback form where output is never shown, so the email parameter is injected with ||ping -c 10 127.0.0.1|| to make the server pause ten seconds and prove the command ran
OS command injection 4 min -
Insane
0.CL request smuggling
0.cl smuggling from the http/1 must die research, where a Content-Length written with a space before the colon makes the front end read no body while the back end reads one, so an early response gadget and a double desync leave a User-Agent xss waiting in front of carlos's homepage request to run alert()
HTTP request smuggling 8 min -
Insane
Server-side pause-based request smuggling
pause based smuggling where the front end streams bytes to a buggy apache back end, so sending a POST /resources header then pausing 61 seconds fires an instant redirect and holds the connection open, turning the delayed body into a smuggled admin request
HTTP request smuggling 7 min -
Insane
Client-side desync
client side desync where no front end is needed, an endpoint that ignores Content-Length plus browser connection reuse lets a victim's own browser smuggle a request against itself, captured into a stored comment via fetch to leak and reuse their session cookie
HTTP request smuggling 13 min
Nothing matched that.
No writeups here yet. Try a broader tag, or clear the filter to see everything.
Clear filters