๊ฐ€์ž… ํ›„ ์ดˆ๋Œ€ ๋งํฌ๋ฅผ ๊ณต์œ ํ•˜๋ฉด ๋™์˜์ƒ ์žฌ์ƒ ๋ฐ ์ดˆ๋Œ€ ๋ณด์ƒ์„ ๋ฐ›์„ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

Abhishek
@aacle_
Building @Vulncure โšก| Helping founders fix vulnerabilities before hackers find them. Talk to me about: Bug Bounties, LLM Security & React.
๊ฐ€์ž… June 2017
292 ํŒ”๋กœ์ž‰ ์ค‘    49.3K ํŒฌ
My favorite bug class right now: **argument injection.** ๐ŸŽฏ Jellyfin had an unauthenticated endpoint that could turn FFmpeg into a file reader. ๐Ÿ“ `/Videos/{itemId}/stream` An unvalidated query parameter was passed straight into FFmpeg. The trick wasn't `;id` or shell injection. โŒ It was an `-vf drawtext` filter that made FFmpeg render `[/]etc[/]shadow` into the video response. ๐Ÿ‘€ โœ… No shell needed โœ… No semicolon ๐Ÿ’€ Just argument injection.
๋” ๋ณด๊ธฐ