Project Sekai
🔒 CrewCTF 2023 / ✅-web-safe_proxy
Sutx
BOT
07/07/2023 10:02 PM
safe_proxy - 1000 points
Category:
Web
Description:
Deno sandbox prevents SSRF, right? Author : Satoooon
http://safe-proxy-web.chal.crewc.tf:8083/
Files:
https://crewc.tf/files/20f82440902ad65db66ff982bfe3d94e/safe_proxy.zip?token=eyJ1c2VyX2lkIjoyMSwidGVhbV9pZCI6MTYsImZpbGVfaWQiOjMzfQ.ZKjt8A.ikU0WGDyMFujdkJrVl_-bLQ4yrQ
Tags:
No tags.
Sutx
pinned
a message
to this channel.
07/07/2023 10:02 PM
Sutx
BOT
07/08/2023 1:41 AM
@rubiya
wants to collaborate
Sutx
BOT
07/08/2023 2:31 AM
@Violin
wants to collaborate
rubiya
07/08/2023 2:54 AM
why /proxy doesn't work?
Sutx
BOT
07/08/2023 3:11 AM
@irogir
wants to collaborate
irogir
07/08/2023 3:15 AM
too lazy to provide a working compose
(edited)
rubiya
why /proxy doesn't work?
irogir
07/08/2023 3:38 AM
what urls did you specify?
03:38
we are restricted to
--allow-net="0.0.0.0:8080,$PROVIDER_HOST"
irogir
07/08/2023 4:12 AM
fetch supports more protocols
04:12
code is in ext/fetch/lib.rs:253
04:13
we
could
use file prot to read from cwd (it is allowed by the rules)
04:14
and maybe the contents of requests are cached, so we could recover the flag from .cache
Sutx
BOT
07/08/2023 4:22 AM
@jayden
wants to collaborate
irogir
07/08/2023 4:29 AM
@jayden
can you build the web docker?
irogir
07/08/2023 4:38 AM
yeah seems like just finding out how this hash is built, have local solve
irogir
yeah seems like just finding out how this hash is built, have local solve
sahuang
07/08/2023 4:54 AM
https://discord.com/channels/959047109015904306/959060331496345601/1127206031529869374
04:54
is this the issue?
sahuang
https://discord.com/channels/959047109015904306/959060331496345601/1127206031529869374
irogir
07/08/2023 4:55 AM
dont have access to this link, mind sharing ss
sahuang
07/08/2023 4:56 AM
someone ask it's the docker working properly? i get the following error ERROR: failed to solve: error getting credentials - err: exit status 1, out: ``
irogir
07/08/2023 4:56 AM
nah, i just have skill issues reading rust code
sahuang
07/08/2023 4:56 AM
o ok
irogir
07/08/2023 5:04 AM
the token from the dumped sqlite btw
http://safe-proxy-flag-provider:8082/?token=5a35327045b0ec9159cc188f643e347f
Sutx
BOT
07/08/2023 5:30 AM
@Legoclones
wants to collaborate
05:31
✅ Challenge solved.
Legoclones
07/08/2023 5:32 AM
gg web maxxed lol
irogir
07/08/2023 5:32 AM
crew{file://_SSRF_in_modern_6f4544ec261423ce}
ig i could have just adjusted the token in the image instead of trying to get that cs gen working
Legoclones
gg web maxxed lol
sahuang
07/08/2023 5:59 AM
more in an hour
Legoclones
07/08/2023 6:00 AM
I thought in 4 hours?
sahuang
07/08/2023 6:00 AM
oh maybe yeah
06:00
timezoned
Legoclones
07/08/2023 6:00 AM
yeah
Exported 32 message(s)