Rayhan0x01's Blog

DevOps and AppSec Practitioner

17 November 2022

Business CTF 2022: H2 Request Smuggling and SSTI - Phishtale

This blog post will cover the creator’s perspective, challenge motives, and the write-up of the web challenge Phishtale from Business CTF 2022. The challenge involves exploiting an HTTP/2 Request Smuggling vulnerability and bypassing Twig Sandbox Policy for Server-Side Template Injection to gain RCE.

Tags :

[ HTB  business-ctf  ctf  web  request-smuggling  ssti  http2  cve-2021-36740  cve-2022-23614  rce  write-up  ]