CTF Writeups

3v@l — Exploiting an eval-based Loan Calculator (picoCTF)

A vulnerable loan calculator used eval on user-supplied expressions. Because the evaluator ran Python and performed only a textual blacklist of dangerous keywords in the submitted payload (not on strings constructed at runtime), it was possible to craft a payload that decodes and executes a harmless-looking string, which, when decoded at runtime, performs the file read of /flag.txt. Platform: picoCTFChallenge: 3v@lDifficulty: Medium Recon — understanding

,