Rayhan0x01's Blog

DevOps and AppSec Practitioner

10 June 2022

CA CTF 2022: Exploiting Redis Lua Sandbox Escape RCE with SSRF - Red Island

In this write-up, we’ll go over the web challenge Red Island, rated as medium difficulty in the Cyber Apocalypse CTF 2022. The solution requires exploiting a Server-Side Request Forgery (SSRF) vulnerability to perform Redis Lua sandbox escape RCE (CVE-2022-0543) with Gopher protocol.


Tags :

[ HTB  CA-CTF  ctf  web  ssrf  node-libcurl  gopher  redis  cve-2022-0543  rce  write-up  ]