logo

SensePost Challenge – Winners and Walkthrough

ID: 6169aba1-b910-5ce6-95fb-7ee97fb6e220

STIX ID: report--6169aba1-b910-5ce6-95fb-7ee97fb6e220

Feed Name: SensePost Blog

Threat Score
70/100

Date Published: 2014-06-27

Date Updated: 2026-04-29

...
...

This walk-through documents a Black Hat challenge that demonstrates multiple serious web‑application flaws: XXE vulnerabilities used to read and exfiltrate local files (including use of external DTDs and php://filter base64 encoding) and injection of PHP into generated pages (via CDATA/encoded payloads) to achieve remote command execution. The report includes working payloads, HTTP request examples, and verification steps showing how each flag was obtained.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.