
Tips & Tricks For Web Challenges by PinkDraconian | Cyber Apocalypse 2022 Hacking Workshops
Source: YouTube · Hack The Box · published May 26, 2022 · 29:09
Pink Draconian presents a walkthrough of two HackTheBox Cyber Apocalypse CTF web challenges, demonstrating a client-side XSS attack that bypasses CSP and a server-side exploit using prototype pollution 1:09-1:36.
Key Takeaways:
• The first challenge involves accessing a localhost-only endpoint by exploiting a bot that visits a feedback list page, requiring an XSS payload 2:55-3:08.
• A restrictive Content Security Policy (CSP) is bypassed by abusing a whitelisted CDN hosting a vulnerable AngularJS library to execute malicious scripts 13:22-13:52.
• The final payload fetches the protected flag from the internal page and exfiltrates it to an external server controlled by the attacker 15:56-16:22.
• The second challenge exploits a prototype pollution vulnerability in the flat package v5.0.0 to manipulate the Pug templating engine 21:28-22:00.
• By triggering an Abstract Syntax Tree (AST) injection through the polluted prototype, the attacker achieves Remote Code Execution (RCE) and retrieves the flag via a reverse shell 26:28-26:52.
The talk concludes by emphasizing the importance of researching advanced vulnerabilities like AST injection and continuous learning in the cybersecurity field 27:28-28:00.
Sources:
- 1:09-1:36 Introduction to the web challenges and topics.
- 2:55-3:08 Explanation of the localhost restriction and bot target.
- 13:22-13:52 Identifying the CSP bypass using AngularJS.
- 15:56-16:22(https://www.youtube.c
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
peter ghonian i started watching his videos while i was in hackthebox and it was like a young talent i think he was messaged me that hello i do these videos and it was him like okay you are amazing and we started the series with him uh now he is competing that's why he cannot be lying with us today he's competing at the european challenge and uh representing not to the worldwide challenge that europe has their own group america has their own group um latin america has their own group so asia has their own group africa has their own group australia has their own group and they fight all with each other it is with young talents you can check it out this icc so he has peter gonyan because he's so young and he's so talented he's playing there with us today but we couldn't miss him from the tal…