Media Badge
22 Videos
20 Exercises
The media badge is our set of exercises created to teach you how to abuse applications that allows you to upload or retrieve files in different formats: PDF, Images, Videos and use this behaviour to gain code execution or arbitrary file read
Exercises
Coming soon
Easy
PENTESTERLAB
ODF XXE
- This exercise covers the exploitation of an XXE in an ODF Parser
- Takes -- on average
Coming soon
Medium
PENTESTERLAB
Latex: --shell-escape
- This exercise covers how one can leverage latex when pdflatex is used with the --shell-escape option to gain command execution.
- Takes -- on average
- Ruby/Latex
Coming soon
Medium
PENTESTERLAB
CVE-2022-24720
- This exercise covers how one can leverage image processing in ActiveStorage to gain command execution.
- Takes -- on average
- Ruby/Rails