GitLab 11.4.7 Remote Code Execution - Real World CTF 2018

LrLJuyAdoAg/default.jpg

Video write-up about the Real World CTF challenge "flaglab" that involved exploiting a gitlab 1day. Actually two CVEs are combined to achieve full remote code execution:

CVE-2018-19571 (SSRF) + CVE-2018-19585 (CRLF) = RCE

flaglab - docker-compose: https://gist.github.com/LiveOverflow/...
Release: https://about.gitlab.com/2018/11/28/s...

-=[ ๐Ÿ”ด Stuff I use ]=-

→ Microphone:* https://amzn.to/2LW6ldx
→ Graphics tablet:* https://amzn.to/2C8djYj
→ Camera#1 for streaming:* https://amzn.to/2SJ66VM
→ Lens for streaming:* https://amzn.to/2CdG31I
→ Connect Camera#1 to PC:* https://amzn.to/2VDRhWj
→ Camera#2 for electronics:* https://amzn.to/2LWxehv
→ Lens for macro shots:* https://amzn.to/2C5tXrw
→ Keyboard:* https://amzn.to/2LZgCFD
→ Headphones:* https://amzn.to/2M2KhxW

-=[ ❤️ Support ]=-

→ per Video: https://www.patreon.com/join/liveover...
→ per Month: https://www.youtube.com/channel/UClcE...

-=[ ๐Ÿ• Social ]=-

→ Twitter: https://twitter.com/LiveOverflow/
→ Website: https://liveoverflow.com/
→ Subreddit: https://www.reddit.com/r/LiveOverflow/
→ Facebook: https://www.facebook.com/LiveOverflow/

-=[ ๐Ÿ“„ P.S. ]=-

All links with "*" are affiliate links.
LiveOverflow / Security Flag GmbH is part of the Amazon Affiliate Partner Programm.

#CTF #CVE

LrLJuyAdoAg/default.jpg
GitLab 11.4.7 Remote Code Execution - Real World CTF 2018 GitLab 11.4.7 Remote Code Execution - Real World CTF 2018 Reviewed by Anonymous on April 21, 2019 Rating: 5