Overview
Learn how to exploit server-side XSS in PDF.js through a detailed walkthrough video of the "Upload" web challenge from Akasec CTF 2024. Follow along with a comprehensive demonstration of source code analysis, exploitation of the recent CVE-2024-4367 vulnerability in PDF.js, and Server-Side Request Forgery (SSRF) techniques. Gain practical experience in web security testing and CTF challenge solving through this beginner-friendly tutorial that breaks down complex concepts into manageable steps. Access additional resources, write-ups, and social media links to further enhance your understanding of web security concepts and CTF methodologies.
Syllabus
Start
Source code review
XSS CVE-2024-4367
SSRF
End
Taught by
CryptoCat