<?xml version="1.0" encoding="utf-8"?>
<!-- generator="FeedCreator 1.7.2-ppt DokuWiki" -->
<?xml-stylesheet href="http://wiki.zenk-security.com/lib/exe/css.php?s=feed" type="text/css"?>
<rdf:RDF
    xmlns="http://purl.org/rss/1.0/"
    xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
    xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
    xmlns:dc="http://purl.org/dc/elements/1.1/">
    <channel rdf:about="http://wiki.zenk-security.com/feed.php">
        <title>Zenk - Security dctf_qual_2014</title>
        <description></description>
        <link>http://wiki.zenk-security.com/</link>
        <image rdf:resource="http://wiki.zenk-security.com/lib/tpl/dokuwiki/images/favicon.ico" />
       <dc:date>2026-05-04T01:28:09+02:00</dc:date>
        <items>
            <rdf:Seq>
                <rdf:li rdf:resource="http://wiki.zenk-security.com/doku.php?id=dctf_qual_2014:web300&amp;rev=1425282812&amp;do=diff"/>
            </rdf:Seq>
        </items>
    </channel>
    <image rdf:about="http://wiki.zenk-security.com/lib/tpl/dokuwiki/images/favicon.ico">
        <title>Zenk - Security</title>
        <link>http://wiki.zenk-security.com/</link>
        <url>http://wiki.zenk-security.com/lib/tpl/dokuwiki/images/favicon.ico</url>
    </image>
    <item rdf:about="http://wiki.zenk-security.com/doku.php?id=dctf_qual_2014:web300&amp;rev=1425282812&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2015-03-02T08:53:32+02:00</dc:date>
        <title>dctf_qual_2014:web300</title>
        <link>http://wiki.zenk-security.com/doku.php?id=dctf_qual_2014:web300&amp;rev=1425282812&amp;do=diff</link>
        <description>D-CTF 2014 Qualifications : WEB300

On repère une LFI : 

http://10.13.37.13/?page=/etc/passwd

En regardant la source de la page on constate que les images sont chargées via un script PHP nommé tt.php.

En cherchant un peu on se rend compte qu'il s'agit de TimThumb 1.33.</description>
    </item>
</rdf:RDF>
