Skip to content

Commit

Permalink
One more spelling correction, I promise
Browse files Browse the repository at this point in the history
  • Loading branch information
Josh-00FF00 committed Nov 30, 2018
1 parent 055632d commit bd54ec6
Showing 1 changed file with 1 addition and 1 deletion.
2 changes: 1 addition & 1 deletion _posts/2018-11-29-seccon_ghostkingdom.markdown
Original file line number Diff line number Diff line change
Expand Up @@ -143,7 +143,7 @@ The upload looks like this after you've selected a photo:
![upload]({{site.url}}/images/seccon18/convert.png)


This is just a random JPG I had in my downloads folder form another CTF we competed in. Bonus points if you know which CTF it was ;).
This is just a random JPG I had in my downloads folder from another CTF we competed in. Bonus points if you know which CTF it was ;).

Now the really interesting thing here is the "convert" link. I mean it will be, it's the only other thing on the page apart from "back" so that's a bit of a pointless statement. But what I really mean is that "converting" an image is a _very_ strong indicator that we're dealing with an ImageTragick style exploit. Since that's triggered by user controlled input into an ImageMagick command, which `convert` is one of.

Expand Down

0 comments on commit bd54ec6

Please sign in to comment.