Exploit Zip Slip vulnerability in python tarfile | Slippy @ HackTheBox

Published: 25 April 2022
on channel: 0xbro
2,983
56

Slippy is an easy difficulty web challenge from ‪@HackTheBox‬ vulnerable to Zip Slip because of the insecure use of the TarFile's python module "extractall".
Due to the absence of file name checks it is possible to create a malicious archive containing path traversals in order to overwrite other files and obtain remote code execution.

=== Timestamp ===
00:00 - Intro
01:09 - Setting up the challenge environments
02:03 - Analyzing application features and behaviours
03:17 - Analyzing the source code
04:19 - Investigating the core logic of the app
05:09 - Analyzing the Zip Slip vulnerability
06:50 - Exploiting Zip Slip locally
07:15 - Exploiting Zip Slip overwriting the program logic
07:44 - Exploiting Zip Slip injecting __init__.py
09:15 - Reproducing the exploit chain against the remote server
09:48 - Conclusions


If you enjoyed the video leave a like and subscribe to my channel!
For writeups in text format or other articles related to Ethical Hacking go to my blog: https://maoutis.github.io/
---
Would you like to support my work? Offer me a virtual coffee :)
https://www.buymeacoffee.com/0xbro

Check out my socials:
Twitter:   / 0xbro1  
Linkedin:   / mattia-0xbro-brollo-b4129614b  

External resources:
https://snyk.io/research/zip-slip-vul...
https://github.com/snyk/zip-slip-vuln...
   • Critical .zip vulnerabilities? - Zip ...  
   • ZipSlip w/ TAR & Server-Side Template...  
   • HTB x UNI CTF 2021: HackTheBox Univer...  

Tags:
#ZipSlip #PathTraversal #HackTheBox #WebHacking #CTF #WebChallenge


On this page of the site you can watch the video online Exploit Zip Slip vulnerability in python tarfile | Slippy @ HackTheBox with a duration of hours minute second in good quality, which was uploaded by the user 0xbro 25 April 2022, share the link with friends and acquaintances, this video has already been watched 2,983 times on youtube and it was liked by 56 viewers. Enjoy your viewing!