GitLab 11.4.7 Remote Code Execution - Real World CTF 2018

Описание к видео GitLab 11.4.7 Remote Code Execution - Real World CTF 2018

Video write-up about the Real World CTF challenge "flaglab" that involved exploiting a gitlab 1day. Actually two CVEs are combined to achieve full remote code execution:

CVE-2018-19571 (SSRF) + CVE-2018-19585 (CRLF) = RCE

flaglab - docker-compose: https://gist.github.com/LiveOverflow/...
Release: https://about.gitlab.com/2018/11/28/s...

=[ ❤️ Support ]=

→ per Video:   / liveoverflow  
→ per Month:    / @liveoverflow  

=[ 🐕 Social ]=

→ Twitter:   / liveoverflow  
→ Website: https://liveoverflow.com/
→ Subreddit:   / liveoverflow  
→ Facebook:   / liveoverflow  

#CTF #CVE

Комментарии

Информация по комментариям в разработке