RealSeek

Description

Author: puck

After I got hacked, I learned to code securely. I added so many filters that no hacker can get through me now

Challengearrow-up-rightMirrorarrow-up-right

Solution

realseek-1

Upgraded version of previous challenge Babyseek

Identify blocked chars:

circle-info

Blocked Chars: 0, 2, 4, 5, 6, 8, 9, f, j, k, v, w, x, y, z, A, B, C, D, E, G, H, J, K, L, M, N, O, P, Q, R, T, U, V, W, X, Y, Z, !, #, %, &, ', +, ,, -, ., /, :, ;, <, =, >, ?, @, ^, _, `, |, ~

Since they are many characters blocked we have to get smart about our payload. From my observation I could use request within the boundaries and after that I built the payload.

Reference: Jinja2 SSTI - without several charsarrow-up-right

Verbose Payload:

Encoded Payload:

circle-info

\137 is _, but in Octal code.

circle-exclamation

Enumerate:

realseek-2

Profit:

realseek-3
circle-check

Last updated