Skip to content

Latest commit

 

History

History
6 lines (5 loc) · 234 Bytes

File metadata and controls

6 lines (5 loc) · 234 Bytes

Cinsects2022 hireme django web app pickle exploit

This is an exploit for the Cinsects 2022 Attack/Defense CTF, leveraging an RCE vulnerability in hireme django web app:

  • fixed known HMAC secret key
  • unpickling user-supplied input