Cyber Apocalypse Day #3 | Escaping filters and stealing flags by @WJ Pearce

Cyber Apocalypse Day #3 | Escaping filters and stealing flags by @WJ Pearce

Source: YouTube · Hack The Box · published Mar 24, 2025 · 21:01

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

The main goal of the Cyber Apocalypse 2025 stream is to teach ethical hackers how to exploit Python's eval function to bypass input filters and retrieve flags in CTF challenges 2:15.

Key Takeaways:
• The challenge involves escaping a Python-based filter by exploiting eval to read a flag file, despite blacklisted commands like os or import 4:48.
• A successful attack uses open() and read() to extract the flag, bypassing restrictions by leveraging allowed functions 16:48.
• A real-world red teaming approach uses a payload script to automate command execution over a remote connection, mirroring actual penetration testing scenarios 18:40.
• The stream emphasizes input validation and trusted inputs, warning against using untrusted user input with eval 19:43.

The event concludes with a daily drawing for prizes, and participants are encouraged to join the Discord for further support 3:55.

Sources:

  • 2:15 Overview of the talk and its focus on escaping filters using Python.
  • 4:48 Discussion of blacklisted functions and how allowed functions like open() and read() are used.
  • 16:48 Demonstration of retrieving the flag via file operations in Python.
  • 18:40 Real-world red teaming approach using automated payloads.
  • 19:43 Key security lesson on input validation and trusted functions.
  • 3:55 I

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

day three of cyber apocalypse 2025 I hope everyone's having a ton of fun so far uh we know that those some challenges have certainly been interesting but I'm glad that everyone's having fun so uh thank you again everyone who is playing uh we have a couple quick announcements today including our daily drawing uh and then we will get into our talk for today uh the talk for today that's going to be coming up is uh escaping filters and stealing Flags by WJ Piers I'll get to that in just a moment uh let's go ahead and go through a quick run of show just to uh make sure that everybody has the info that they need uh as always uh or rather not as always uh for this event this is going to end on the 26th that is this upcoming Wednesday uh I will go ahead let me link the event uh page in chat there …