python:3.7.11-buster vulnerable into CVE-2022-44268 (Exiftool arbitrary file read)

Event Name TPCTF
GitHub URL -
Challenge Name thumbor 1

pandoc/core:2.18-ubuntu vulnerable into cve-2023-38633 (LibRSVG)

Event Name TPCTF
GitHub URL -
Challenge Name thumbor 2

There’s

special case where we can make symlink to link to the host container file.

l3hctf 2024

https://s1um4i-official.feishu.cn/docx/QeGGdeyuhoR6kuxCOj8c44wRnne#SfxUd5lMRoxkfCx1G7HcrCTbnob

detailed WU can be see there https://hust-l3hsec.feishu.cn/docx/MZ8SdwSoPo3cBTxOxbGcuUBun4c

ln -sf /flag /app/output.txt

![[Pasted image 20240206174335.png]]

dari analisis ku sih karna /dev/sda2 di mount di /app

/dev/sda2 /app ext4 rw,relatime,errors=remount-ro,stripe=256 0 0