Home / Companies / Snyk / Blog / Post Details
Content Deep Dive

Snyk Fetch the Flag CTF 2023 writeup: Protect The Environment

Blog post from Snyk

Post Details
Company
Date Published
Author
John Hammond
Word Count
243
Company Posts That Month
30
Language
English
Hacker News Points
-
Post removed?
No
Summary

The challenge at Snyk's Fetch the Flag CTF 2023, Protect The Environment, involves a base64 encoded path that breaks Flask's ability to automatically chroot static files, leading to a file inclusion attack. The attacker includes the `/proc/<pid>/environ` file instead of a regular file, exploiting the lack of information about the process ID used by Gunicorn workers. A bash script is provided to solve the challenge using `curl`, base64 encoding, and string manipulation to extract the flag from the encoded path.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.