3 ms·
How exactly would that work? Curl isn't exactly software that can be "hosted" somewhere, and I'm not sure where you'd hide the flag in the software? Either very
by snowmobile 9mo ago
How exactly would that work? Curl isn't exactly software that can be "hosted" somewhere, and I'm not sure where you'd hide the flag in the software? Either very few actual vulns would end up being able to retrieve the flag, or it would be trivial to retrieve the flag without an exploit.
- zvqcMMV6Zcr 9mo agoIn most basic form it would just be form with URL that (lib)curl is later supposed to fetch. And target server (controlled by researcher) is supposed to send payload that triggers RCE in client. Sure, it covers a very narrow scope but I am afraid the bigger issue would be that it is going to get spammed with submitted links. And those links will often be to strait up illegal content, it might not matter that such server instantly deletes all downloaded files.
- StrauXX 9mo agoSimple. You multiple instances with different flags covering different threat models. RCE, file read, etc. You then expose a webapplication for every instance that lets users control only those curl flags, that must be safe to be user controlled in the reapective threat model.