πŸ›‘οΈ Security Lab Track A Β· Web Application Security Β· Stage 9

Track A Β· Stage 9

Web Application Security

Insecure Deserialization (pickle) hardnot started

A 'remember me' cookie is a base64 pickle that the server loads with pickle.loads. Craft a malicious pickle whose __reduce__ executes a command to read the flag.

loading simulator…

Server-Side Template Injection (Jinja2) hardnot started

A greeting feature renders your name through Jinja2 by string-formatting it into the template source. Inject template syntax to execute Python and read the flag.

loading simulator…

Race Condition (double spend) hardnot started

A store gives each account one $10 coupon. The redeem endpoint checks the balance and then deducts it in two non-atomic steps. Redeem concurrently to spend the coupon more than once and buy the $15 flag item.

loading simulator…