
Web CTF challenge highlighting moodle CVE-2025-26529 (in 2 flavors)
I have the following ctf challenge idea:
Now, the attacker sees this as an opportunity to retrieve the flag. But the flag in this case is hidden in an internal endpoint whose access is impossible. The response from this endpoint IS the flag, but you get 403 unauthorized.
[email protected] and attacker.com will contain
a redirection to ANY url (it doesn't matter) appended to it a Cookie stealer.@ref (webfinger): https://www.youtube.com/watch?v=Y26c9MNQLyc You could attach anything to your email address (which is a uri)??
The steps the attacker would go over are:
@ref: https://github.com/moodle/moodle Inspire from reports/... files to carry the live logs feature
Check ./challenge.md