Skip to content

mountassir-cha/LAB19

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

1 Commit
 
 
 
 
 
 
 
 

Repository files navigation

LAB19SECMOBILE - SnakeYAML RCE Exploitation

Flag

PMNSEC{N3'r3_NOT_TOOLS_OF_The_g0v3rmm3n7_OR_4nyOn3_3L5s3}

Structure

  • /payload - Payload YAML pour l'exploitation
  • /scripts - Scripts d'automatisation

Vulnérabilité

CVE-2022-1471 - SnakeYAML Deserialization RCE

Quick Exploit

adb shell mkdir -p /sdcard/Snake
adb push payload/Skull_Face.yml /sdcard/Snake/
adb shell am start -n com.pwnsec.snake/.MainActivity -e SNAKE BigBoss
adb logcat | grep BigBoss

About

Résolution détaillée étape par étape (PwnSec CTF 2024 Mobile Hard)

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

 
 
 

Contributors