Y

YouLibs

Remove Touch Overlay

can you hack this screenshot service?? - CSCG 2021

Duration: 22:48Views: 92.7KLikes: 5.1KDate Created: Aug, 2021

Channel: LiveOverflow

Category: Science & Technology

Tags: containerecscweb hackingliveoverflowbug bountygermanyeuropean cybercapture the flagdockerlive overflowhacking tutorialctfsolutioninternal servicebug bounty huntingtemplate enginessrfchain bugsself-xsscybersecurityhacking tutorial 2021headless chromehow to hackexploit tutorialjinja2cyber security challengewalkthroughcscgself-xss attackethical hackingflaskchaining bugs

Description: I made a web hacking challenge for the Cyber Security Challenge Germany (cscg) 2021. Grab the files: github.com/LiveOverflow/ctf-screenshotter Cyber Security Challenge Germany: cscg.de 00:00 - Introduction to screenshotter app 00:58 - Setup the challenge 01:38 - First overview of functionality 03:07 - Review application architecture 03:51 - The chrome service 04:19 - The main app service 05:07 - Chrome service IP leak 06:22 - The app secret 06:54 - Methodology: go for complex features 09:22 - The flagger/admin service 11:30 - First attack idea: XSS 11:55 - Reviewing flask templates 13:09 - Useless self-XSS? 13:38 - Bypass demo restriction 15:45 - Using the Chrome SSRF? 17:00 - Leak websites of other users 18:31 - THE EXPLOIT! 22:04 - Outro -=[ ❤️ Support ]=- → Support: liveoverflow.com/support → per Video: patreon.com/join/liveoverflow → per Month: youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w/join -=[ 🐕 Social ]=- → Twitter: twitter.com/LiveOverflow → Website: liveoverflow.com → Subreddit: reddit.com/r/LiveOverflow → Facebook: facebook.com/LiveOverflow

Swipe Gestures On Overlay