A Django site Valid XHTML 1.1 Strict Get Firefox

Gu1's Website - Posts taggés « pctf »

PlaidCTF 2011 web 300 "Django...really?"
Par Gu1 le 29/04/2011 à 15:01 tags: memcached, pctf, plaidctf, web, writeup.

Hello,
This writeup will cover a 300points web mission we solved during PlaidCTF 2011. We had access to a simple guestbook with a form. We tried to trigger a bug unsuccessfully. At first, we thought the vulnerability might be a flaw in csrf handling because of the advisory published last february. The app was reacting strangely to the csrf cookie, (re)setting it multiple times, but then the organizers removed the csrf check altogether.

We were stuck at this point until a hint was given: django settings file contained a reference to a memcached server. We hadn't tried to ...

0 Commentaires / Lire la suite...

1
©opyleft Gu1ll4um3r0m41n, 2008-2010. Contact