Blitzprop
Writeup for Blitzprop (Web) - HackTheBox Cyber Apocalypse CTF (2021) ๐
Last updated
Writeup for Blitzprop (Web) - HackTheBox Cyber Apocalypse CTF (2021) ๐
Last updated
To exploit this, you need to use a โprototype pollutionโ vulnerability within the flat library in order to gain RCE against the target. This requires a request to the server to 'pollute' the JavaScript objects, then a second request to trigger the payload. Overall, it was a really interesting box!
Flag: CHTB{p0llute_with_styl3}