Slippy is an easy difficulty web challenge from @HackTheBox vulnerable to Zip Slip because of the insecure use of the TarFile's python module "extractall".
Due to the absence of file name checks it is possible to create a malicious archive containing path traversals in order to overwrite other files and obtain remote code execution.
=== Timestamp ===
00:00 - Intro
01:09 - Setting up the challenge environments
02:03 - Analyzing application features and behaviours
03:17 - Analyzing the source code
04:19 - Investigating the core logic of the app
05:09 - Analyzing the Zip Slip vulnerability
06:50 - Exploiting Zip Slip locally
07:15 - Exploiting Zip Slip overwriting the program logic
07:44 - Exploiting Zip Slip injecting __init__.py
09:15 - Reproducing the exploit chain against the remote server
09:48 - Conclusions
If you enjoyed the video leave a like and subscribe to my channel!
For writeups in text format or other articles related to Ethical Hacking go to my blog: https://maoutis.github.io/
---
Would you like to support my work? Offer me a virtual coffee :)
https://www.buymeacoffee.com/0xbro
Check out my socials:
Twitter: / 0xbro1
Linkedin: / mattia-0xbro-brollo-b4129614b
External resources:
https://snyk.io/research/zip-slip-vul...
https://github.com/snyk/zip-slip-vuln...
• Critical .zip vulnerabilities? - Zip ...
• ZipSlip w/ TAR & Server-Side Template...
• HTB x UNI CTF 2021: HackTheBox Univer...
Tags:
#ZipSlip #PathTraversal #HackTheBox #WebHacking #CTF #WebChallenge
Nesta página do site você pode assistir ao vídeo on-line Exploit Zip Slip vulnerability in python tarfile | Slippy @ HackTheBox duração hora minuto segundo em boa qualidade , que foi baixado pelo usuário 0xbro 25 Abril 2022, compartilhe o link com seus amigos e conhecidos, no youtube este vídeo já foi visto 2,983 vezes e gostou 56 espectadores. Boa visualização!