SecureStorage
EasyWeb Security
Overview
SCENARIO
A file storage system that hashes your filenames, locks down your storage, and makes bold promises about keeping users within their boundaries. The developer was even generous enough to throw in some extra features to make things convenient.
You have full access to the source code. Read through how the application handles files and objects, understand how JavaScript resolves properties, and find a way to step outside the boundaries the developer was so confident about.
Flag format: flag{}
Infrastructure
- Docker Container — HTTP on port 8000
Provided Files
- SecureStorage.zip (3.0 KB)
Job Positions
Ethical Hacker
Tags
Prototype PollutionDirectory TraversalBroken Access ControlJavascriptServer Misconfiguration