parrot the emu

Description

It is so nice to hear Parrot the Emu talk back

Author: richighimi

#url to play:
https://web-parrot-the-emu-4c2d0c693847.2024.ductf.dev

Vuln - SSTI

You can google ssti payloads.

  • First we'll find subclasses with : {{''.class.mro[1].subclasses()}}

List all the subclasses with numbers (you can paste the following link on browser)

  • Hmm the subprocess.popen is at 213 index.

214 -1 = 213 (0 indexing)

Flag

and we get the flag

DUCTF{PaRrOt_EmU_ReNdErS_AnYtHiNg}

Last updated