Points: 100

Tags: web caddy ssti 

Poll rating:

Caddy webserver is AWESOME, using a neat and compact syntax you can do a lot of powerful things, e.g. wanna know if your browser supports HTTP3? Or TLS1.3? etc

Flag is located at GET /$(head -c 18 /dev/urandom | base64) go fetch it.

Handout: https://github.com/kalmarunionenctf/kalmarctf/tree/main/2024/web/caddy-v2

Writeups

ActionRatingAuthor team
Read writeup
not rated
thehackerscrew
You need to authenticate and join a team to post writeups