Rayhan0x01's Blog

DevOps and AppSec Practitioner

6 June 2022

CA CTF 2022: Exploiting Zip Slip and Pickle Deserialization - Acnologia Portal

In this write-up, we’ll go over the web challenge Acnologia Portal, rated as medium difficulty in the CyberApocalypse CTF 2022. The solution requires exploiting a blind-XSS vulnerability and performing CSRF to upload a zip file for arbitrary file injection, crafting Flask-Session cookie for deserialization to get remote code execution.


Tags :

[ HTB  CA-CTF  ctf  web  cookie-forgery  blind-xss  csrf  flask-session  pickle-deserialization  deserialization  zip-slip  rce  write-up  ]