video thumbnail 22:48
can you hack this screenshot service?? - CSCG 2021

2021-08-19

[public] 13.9K views, 6.22K likes, 16.0 dislikes audio only

channel thumbLiveOverflow

I made a web hacking challenge for the Cyber Security Challenge Germany (cscg) 2021.

Grab the files: https://github.com/LiveOverflow/ctf-screenshotter

Cyber Security Challenge Germany: https://www.cscg.de/

00:00 - Introduction to screenshotter app

00:58 - Setup the challenge

01:38 - First overview of functionality

03:07 - Review application architecture

03:51 - The chrome service

04:19 - The main app service

05:07 - Chrome service IP leak

06:22 - The app secret

06:54 - Methodology: go for complex features

09:22 - The flagger/admin service

11:30 - First attack idea: XSS

11:55 - Reviewing flask templates

13:09 - Useless self-XSS?

13:38 - Bypass demo restriction

15:45 - Using the Chrome SSRF?

17:00 - Leak websites of other users

18:31 - THE EXPLOIT!

22:04 - Outro

-=[ ❤️ Support ]=-

→ Support: https://liveoverflow.com/support

→ per Video: https://www.patreon.com/join/liveoverflow

→ per Month: https://www.youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w/join

-=[ 🐕 Social ]=-

→ Twitter: https://twitter.com/LiveOverflow/

→ Website: https://liveoverflow.com/

→ Subreddit: https://www.reddit.com/r/LiveOverflow/

→ Facebook: https://www.facebook.com/LiveOverflow/


Introduction to screenshotter app
/youtube/video/FCjMoPpOPYI?t=0
Setup the challenge
/youtube/video/FCjMoPpOPYI?t=58
First overview of functionality
/youtube/video/FCjMoPpOPYI?t=98
Review application architecture
/youtube/video/FCjMoPpOPYI?t=187
The chrome service
/youtube/video/FCjMoPpOPYI?t=231
The main app service
/youtube/video/FCjMoPpOPYI?t=259
Chrome service IP leak
/youtube/video/FCjMoPpOPYI?t=307
The app secret
/youtube/video/FCjMoPpOPYI?t=382
Methodology: go for complex features
/youtube/video/FCjMoPpOPYI?t=414
The flagger/admin service
/youtube/video/FCjMoPpOPYI?t=562
First attack idea: XSS
/youtube/video/FCjMoPpOPYI?t=690
Reviewing flask templates
/youtube/video/FCjMoPpOPYI?t=715
Useless self-XSS?
/youtube/video/FCjMoPpOPYI?t=789
Bypass demo restriction
/youtube/video/FCjMoPpOPYI?t=818
Using the Chrome SSRF?
/youtube/video/FCjMoPpOPYI?t=945
Leak websites of other users
/youtube/video/FCjMoPpOPYI?t=1020
THE EXPLOIT!
/youtube/video/FCjMoPpOPYI?t=1111
Outro
/youtube/video/FCjMoPpOPYI?t=1324
I’m moving, no videos sorry 17,544 views
/youtube/video/9CS3q0uG1LI
Support liveoverflow.com
https://liveoverflow.com/support
CTFs are AWESOME! 78,356 views
/youtube/video/L2C8rVO2lAg