Ir al contenido
cyberhub.es
  • Home
  • CTFs resueltos
    • PicoCTF
      • PicoCTF 2024 writeup
  • Portswigger Lab writeup
    • Access control
    • API Testing
    • CORS
    • Cross-site scripting
    • CSRF
    • File upload
    • GraphQL API vulnerabilities
    • NoSQL injection
    • OS command injection
    • Path traversal
    • SQL injection
    • SSRF
    • Web LLM attacks
    • WebSockets
  • Home
  • CTFs resueltos
    • PicoCTF
      • PicoCTF 2024 writeup
  • Portswigger Lab writeup
    • Access control
    • API Testing
    • CORS
    • Cross-site scripting
    • CSRF
    • File upload
    • GraphQL API vulnerabilities
    • NoSQL injection
    • OS command injection
    • Path traversal
    • SQL injection
    • SSRF
    • Web LLM attacks
    • WebSockets

Categoría: Web LLM attacks

Exploiting vulnerabilities in LLM APIs writeup

Descripción This lab contains an OS command injection vulnerability that can be exploited via its APIs. You can call these APIs via the LLM. To solve the lab, delete the morale.txt file from Carlos’ home directory. Required knowledgeTo solve this lab, you’ll need to know: For more information, see our OS command injection topic. Exploiting […]

Exploiting LLM APIs with excessive agency writeup

Descripción To solve the lab, use the LLM to delete the user carlos. Required knowledgeTo solve this lab, you’ll need to know: For more information, see our Web LLM attacks Academy topic. Exploiting LLM APIs with excessive agency writeup Entramos en el laboratorio y lo exploramos: En el apartado de «Live chat», le decimos a […]

cyberhub.es
  • Política de Cookies

Todos los derechos reservados