Websocket SQLi and Weak JWT Signing Key - "Bug Report Repo" [INTIGRITI 1337UP LIVE CTF 2023]

แชร์
ฝัง
  • เผยแพร่เมื่อ 18 ธ.ค. 2024

ความคิดเห็น • 22

  • @_CryptoCat
    @_CryptoCat  ปีที่แล้ว +5

    4:20 I meant the other way round xD this challenge used SQLite instead of MySQL!

  • @chample1
    @chample1 ปีที่แล้ว +3

    Thanks for idea of brute forcing signature key, that's helped me

    • @_CryptoCat
      @_CryptoCat  ปีที่แล้ว +1

      Perfect! Welcome 💜

  • @__-tc3sr
    @__-tc3sr ปีที่แล้ว +2

    Awesome challenge :O

  • @ragnarlothbrok367
    @ragnarlothbrok367 ปีที่แล้ว +2

    Dope shit, homie

  • @piratica-zq5my
    @piratica-zq5my ปีที่แล้ว +3

    Great video bro 😊

  • @pandorian7
    @pandorian7 หลายเดือนก่อน +1

    holy shit amazing that bool char retrival thing. this that a standerd technique in ctfs or something we need to brainstroam

    • @_CryptoCat
      @_CryptoCat  หลายเดือนก่อน +1

      Boolean/error/time-based SQLi is common, but I haven't seen many challenges that do it over websocket!

  • @BabeRyHellCat
    @BabeRyHellCat ปีที่แล้ว +2

    Thank you for the video. However, I would like to see more videos that include all of the categories listed above. XD

    • @_CryptoCat
      @_CryptoCat  ปีที่แล้ว

      I'm gonna make some more, any challs in particular?

    • @BabeRyHellCat
      @BabeRyHellCat ปีที่แล้ว +1

      @@_CryptoCat I have done all the challenges in the warm-up category. But in other categories of the challenge, I can't solve even one. Because I have just started CTF for 4 months. I watched all your walk-through videos to learn.

    • @_CryptoCat
      @_CryptoCat  ปีที่แล้ว +1

      @@BabeRyHellCat No problem! I'm gonna try and release a video per day (alternating on my channel and intigriti's) for at least the next week, maybe longer if they are getting a good reception 😊

    • @BabeRyHellCat
      @BabeRyHellCat ปีที่แล้ว +1

      @@_CryptoCat thank you so much❤️

  • @xab5862
    @xab5862 ปีที่แล้ว +3

    as a beginner i found this challenge hella hard , any tips to improve on this category of challenges?

    • @_CryptoCat
      @_CryptoCat  ปีที่แล้ว

      It's a very niche topic and definitely takes some time, I made an "intro to pwn" series which might help: th-cam.com/video/wa3sMSdLyHw/w-d-xo.html

  • @hssain.aitkadir
    @hssain.aitkadir 11 หลายเดือนก่อน +2

    Actually, you don't need to use middleware sqlmap supports web sockets, great writeup tho

    • @_CryptoCat
      @_CryptoCat  11 หลายเดือนก่อน +1

      Oh wow, really.. Did you solve this one with SQLMap, without the middleware? Don't think it worked for me 🤔

  • @entertainment_in_blood
    @entertainment_in_blood 8 หลายเดือนก่อน +1

    where can i find this challenge because the CTF is ended right? so have you uploaded this ctf anywhere?

    • @_CryptoCat
      @_CryptoCat  8 หลายเดือนก่อน

      Should still be up: ctf.intigriti.io/challenges