RSSAmplifier

Blog

Orange Tsai

blog.orange.twRSS feed ↗100 posts

Latest posts

(繁中) The Art of PHP — My CTF Journey and Untold Stories!

這是一篇為了《PHRACK》所撰寫的文章!雖然來不及趕上它最輝煌的年代,但也深知其對「駭客文化」不可抹滅的重要性 —— 從計算機第一個揭開 Stack Buffer Overflow 神秘面紗的經典啟蒙,到現今所有 SQL Injection 攻擊的奠基之作,再到 Nmap 第一份原始碼的發布,以及出現在無數影視作品、控訴著「若我有罪,也是好奇心讓我犯罪」的《駭客宣言》…… 時至今日,四十年過去了,不知多少經典由此而生、藉其傳遞著知識,並啟發了一代又一代的駭客!

The Art of PHP — My CTF Journey and Untold Stories!

This is my article featured in the PHRACK 40th Anniversary Release 🎉! It’s kinda a love letter to those CTF players and PHP nerds. Hope all the credit goes to the right people!

從 Web 狗的視角看 OSEE — 從 0.1 開始的 Advanced Windows Exploitation 考試

✅:『課程結束後一年內要考到 OSEE 證

WorstFit: Unveiling Hidden Transformers in Windows ANSI!

(繁中) Confusion Attacks: Exploiting Hidden Semantic Ambiguity in Apache HTTP Server!

📌 [ 繁體中文 | <a href="https://blog.orange.tw/2024/08/confusion-at

Confusion Attacks: Exploiting Hidden Semantic Ambiguity in Apache HTTP Server!

📌 [ 繁體中文 | <a href="https://blog.orange.tw/2024/08/confusion-at

CVE-2024-4577 - Yet Another PHP RCE: Make PHP-CGI Argument Injection Great Again!

📌 [ 繁體中文 | <a hr

從 2013 到 2023: Web Security 十年之進化與趨勢!

TL;DR for Hackers & Researchers: this is a more conceptual talk for web developers. All are in Mandarin but you can check the slides

A New Attack Surface on MS Exchange Part 4 - ProxyRelay!

This is a

Let&#39;s Dance in the Cache - Destabilizing Hash Table on Microsoft IIS!

A New Attack Surface on MS Exchange Part 3 - ProxyShell!

P.S. Th

A New Attack Surface on MS Exchange Part 2 - ProxyOracle!

Hi, this i

A New Attack Surface on MS Exchange Part 1 - ProxyLogon!

The series

A Journey Combining Web Hacking and Binary Exploitation in Real World!

Hi, this blog post is just a short post to address the technique part in one of my Red Team cases last year. I believe it’s worth sharing

How I Hacked Facebook Again! Unauthenticated RCE on MobileIron MDM

📌 [ 繁體中文 | <a href="

你用它上網,我用它進你內網! 中華電信數據機遠端代碼執行漏洞

For non-native readers, this is a writeup of

An analysis and thought about recently PHP-FPM RCE (CVE-2019-11043)

First of all, this is such a really interesting bug! From a small memory defect to code execution. It combines both binary and web techni

Attacking SSL VPN - Part 3: The Golden Pulse Secure SSL VPN RCE Chain, with Twitter as Case Study!

Aut

Attacking SSL VPN - Part 2: Breaking the Fortigate SSL VPN

Autho

Attacking SSL VPN - Part 1: PreAuth RCE on Palo Alto GlobalProtect, with Uber as Case Study!

Author: Ora

A Wormable XSS on HackMD!

在 Web Security 中,我喜歡伺服器端的漏洞更勝於客戶端的漏洞!(當然可以直接拿 shell 的客戶端洞不在此限XD) 因為可以直接控制別人的伺服器對我來說更有趣! 正因如此,我以往的文章對於 XSS 及 CSRF 等相關弱點也較少著墨(仔細翻一下也只有 2018

Hacking Jenkins Part 2 - Abusing Meta Programming for Unauthenticated RCE!

📌 [ 繁體中文 | <a hre

Hacking Jenkins Part 1 - Play with Dynamic Routing

📌 [ 繁體中文 | English ]

HITCON CTF 2018 - One Line PHP Challenge

In every year’s HITCON CTF, I will prepare at least one PHP exploit challenge which the source code is very straightforward, short and ea

How I Chained 4 Bugs (Features?) into RCE on Amazon Collaboration System

Hi! This is th

圖床

DEBUG </

Google CTF 2018 Quals Web Challenge - gCalc

gCalc is the web challenge in Google CTF 2018 quals and only 15 teams solved during 2 days’ competition! This challenge is a ver

Pwn a CTF Platform with Java JRMP Gadget

打 CTF 打膩覺得沒啥新鮮感嗎,來試試打掉整個 CTF 計分板吧! 前幾個月,剛好看到某個大型 CTF 比賽開放註冊,但不允許台灣參加有點難過 :( 看著官網最下面發現是 FlappyPig 所主辦,又附上 <a href="https://github.c

PHP CVE-2018-5711 - Hanging Websites by a Harmful GIF

Recently, I reviewed several Web frameworks and language implementations, and found some vulnerabilities. This is an simple and

How I Chained 4 vulnerabilities on GitHub Enterprise, From SSRF Execution Chain to RCE!

Hi, it’s been a long time since my last blog post. In the past few months, I spent lots of time preparing for the talk of <a href=

GitHub Enterprise SQL Injection

<a href="

[隨筆] Java Web 漏洞生態食物鏈

本來這篇文章叫做 HITCON CTF 2016 初賽出題小記的,可是擺著擺著就兩個月過去惹~ 轉來寫寫跟 Java 有關的東西XD <a href="#關於序" class="headerlink" title="關於序"

Collection of CTF Web Challenges I made

把出過的 CTF Web 題都整理上 GitHub 惹,包括原始碼、解法、所用到技術、散落在外的 Write ups 等等 This is the repository of CTF Web challenges I made. It contains cha

HITCON 2016 投影片 - Bug Bounty 獎金獵人甘苦談 那些年我回報過的漏洞

This is my talk about being a Bug Bounty Hunter at HITCON Community 2016 . It shared some of my

How I Hacked Facebook, and Found Someone&#39;s Backdoor Script

Uber 遠端代碼執行- Uber.com Remote Code Execution via Flask Jinja2 Template Injection

好久沒 po 文了XD 幾天前,Uber

HITCON CTF 2015 Quals & Final 心得備份

當初好像沒留底稿只發布在 Facebook 跟烏雲,今天睡醒發現又有人在轉貼這篇,想說留個備份好了XD <a href="https://www.facebook.com/notes/orange-tsai/hitcon-ctf-2015-qual

Google & Facebook Bug Bounty GET

先說這篇純粹炫耀文xD 暨 2013 年 Yahoo 開始有 Bug Bounty 那時搶個流行找了兩個漏洞回報 Yahoo 然後 <a href="

AIS3 Final CTF Web Writeup (Race Condition & one-byte off SQL Injection)

這次為了 AIS3 Final CTF 所出的一道題目,這題在這以初新者導向中的比賽中相對難,不過其中的觀念很有趣,在解題中什麼都給你了就是找不到洞但經人一解釋就會有豁然開朗覺得為什麼自己沒想到的感覺 <

Remote Code Execution through GDB Remote Debugging Protocol

在準備 DEFCON CTF 時額外想到的小玩具,很多人使用 GDB remote debugging 時為了方便遠端使用,會將 port 綁在 0.0.0.0 上使得攻擊者可以連接上做一些事情 至於可以做哪些事情,不來個遠端代碼執行就不好玩了XD <

HITCON 2015 Community 演講投影片 - 那些 Web Hacking 中的奇技淫巧

噗,在 HITCON 2015 Community 的投影片,講一些好玩的特性跟技巧! <a href="https://github.com/orangetw/My-Presentation-Slides/blob/main/dat

2015 烏雲峰會演講投影片 「關於 HITCON CTF 的那些事 之 Web 狗如何在險惡的 CTF 世界中存活?」

應邀以 HITCON CTF 隊長的身份到 烏雲峰會 講一下過去比賽中遇到的一些趣事,順便解釋一下許多人好奇 HITCON 以及 217, BambooFox 的關係,基本上就是獨立的三支隊伍<

講個秘訣 - 0ctf Final 0cms

這次跟著 217 到上海參加由 0ops 舉辦的 0ctf 決賽 總體來說這次是我打過最爽的一次 Attack &

Web 狗沒人權 TAT?

花了很大力氣蒐集了許多資訊,花了幾個月模擬著可能的突破口一個個檢視,終於發現某個網路邊界有 SQL Injection 可

Bypassing open_basedir and disable_functions by Using PHP Use-After-Free Vulnerability

DEBUG 在滲透入侵 VPS 之類的主機常常會有 open_basedir 以及 disable_fun

Boston Key Party CTF 2015 [Harvard Square] [Andrew & Broadway] Write-ups

Boston Key Party 是今年 Defcon CTF 的倒數第二場資格賽,雖然只拿了 第二名 不過由於冠軍的 PPP 已經確定保送所以應該是可以遞補上今年 Defcon 決賽資

103 年資安技能金盾獎

紀錄一下XD 103 年資安技能金盾獎,台科大 「一輩子的明太子大食團」,冠軍! (圖文不符,放張圖好像比較有內容點)</

Hack in the Box 2014 CTF Writeup - KeygenMe with RSA

這次被以 HITCON 的身份邀請到馬來西亞參加 HITB 2014 CTF ,照慣例來寫篇 Write Up

HITCON Won the 2nd in DEFCON 22 CTF Final

<a href="http://hitcon.org/

Defcon CTF Quals 2014 - Nonameyet write up

記錄一下,Defcon 是世界駭客 CTF 比賽最盛大的賽事,每年都是每個國家資安社群比拼較勁的地方,前十二強可以進入八月在 Las Vegas 拉斯維加斯舉辦的決賽,在現場進行實際網路攻防的 Attack & Defense CTF 的比賽! 在今