Guild icon
Project Sekai
🔒 CrewCTF 2023 / ✅-web-safe_proxy
Avatar
safe_proxy - 1000 points
Category: Web Description: Deno sandbox prevents SSRF, right? Author : Satoooon http://safe-proxy-web.chal.crewc.tf:8083/ Files:Tags: No tags.
Sutx pinned a message to this channel. 07/07/2023 10:02 PM
Avatar
@rubiya wants to collaborate 🤝
Avatar
@Violin wants to collaborate 🤝
Avatar
why /proxy doesn't work?
Avatar
@irogir wants to collaborate 🤝
Avatar
too lazy to provide a working compose (edited)
Avatar
Avatar
rubiya
why /proxy doesn't work?
what urls did you specify?
03:38
we are restricted to --allow-net="0.0.0.0:8080,$PROVIDER_HOST"
Avatar
fetch supports more protocols
04:12
code is in ext/fetch/lib.rs:253
04:13
we could use file prot to read from cwd (it is allowed by the rules)
04:14
and maybe the contents of requests are cached, so we could recover the flag from .cache
Avatar
@jayden wants to collaborate 🤝
Avatar
@jayden can you build the web docker?
Avatar
yeah seems like just finding out how this hash is built, have local solve
Avatar
Avatar
irogir
yeah seems like just finding out how this hash is built, have local solve
04:54
is this the issue?
Avatar
someone ask it's the docker working properly? i get the following error ERROR: failed to solve: error getting credentials - err: exit status 1, out: ``
Avatar
nah, i just have skill issues reading rust code
Avatar
o ok
Avatar
@Legoclones wants to collaborate 🤝
05:31
✅ Challenge solved.
Avatar
gg web maxxed lol
Avatar
crew{file://_SSRF_in_modern_6f4544ec261423ce} 😔 ig i could have just adjusted the token in the image instead of trying to get that cs gen working
Avatar
Avatar
Legoclones
gg web maxxed lol
more in an hour
Avatar
I thought in 4 hours?
Avatar
oh maybe yeah
06:00
timezoned
Avatar
😂 yeah
Exported 32 message(s)