Explore tweets tagged as #justCTF23
@haqpl
Maciej Piechota
2 years
A while ago I created a challenge for #justCTF23 where players needed to blindly exfiltrate data from MongoDB. Here is my payload which triggers DNS resolution. As far as I know, this is a new technique when having SSRF to Mongo without the ability to read the response 😋🔥 #CTF
Tweet media one
2
17
128