Sign inSign up

dockerbucket/pwn_the_host_server

By dockerbucket

•Updated over 6 years ago

SSRF and Insecure Deserialization based CTF applcaition

Image
1

188

dockerbucket/pwn_the_host_server repository overview

⁠Brief Summary

There are two images for the CTF and they are vulnerable to SSRF as well as Insecure Deserialization. Scenarios implemented on SSRF are not the usual kind and yes the CTF has multiple stages in it. Do remember the findings you get while exploiting the vulnerabilities as a few of them are inter-related

⁠Glimpse on Insecure Deserialization and Server Side Request Forgery

Insecure Deserialization: A vulnerability in which an untrusted or unknown data is used to either inflict a denial of service attack (DoS attack), execute code, bypass authentication or further abuse the logic behind an application.

Server Side Request Forgery: A type of exploit where an attacker abuses the functionality of a server causing it to access or manipulate information in the realm of that server that would otherwise not be directly accessible to the attacker

⁠How do I host the CTF ????

docker run -it -d --name vuln_host dockerbucket/pwn_the_host_server:vulnserver

docker run -it -d --link vuln_host --name main_host -p 6060:3030 -p 22:22 dockerbucket/pwn_the_host_server:main_server /ctf_app

Note: Please use the docker command with tags if you would like to pull the images individually

⁠References

https://www.youtube.com/watch?v=tZil9j7TTps⁠

https://www.youtube.com/watch?v=o-tL9ULF0KI⁠

Thank You Nikolay Ermishkin, Maxim Andreev, Ben Sadeghipour aka nahamsec for the contribution that you have made to the community

Tag summary

Content type

Image

Digest

Size

658.6 MB

Last updated

over 6 years ago

docker pull dockerbucket/pwn_the_host_server:main_server