RSS

Tag Archives: command injection

Mozilla CTF 2012 – 17 : IP Panel

To σενάριο του 17ου Challenge του Mozilla CTF ανέφερε :

“Exploit Mozillas IP Panel! This IP Panel is used for whitelisting IP addresses. We know that the webinterface will call a bash script that will execute an iptables command without validation. Find the flag somewhere in /home/ippanel/ and submit it!

Update:
The files are not actually in the home directory. Look somewhere else. Sorry!”

Read the rest of this entry »

 
1 Comment

Posted by on January 29, 2012 in Capture The Flag, It's Greek to Me

 

Tags: , , ,