
Write Once, Shell Everywhere: Exploiting Arbitrary File Writes for RCE at DEF CON
cybersecurityRCEexploitsDEF CONcontainersbug bountyred teaming
The post summarizes a talk presented at DEF CON's Bug Bounty Village. It introduces a technique catalog designed for distroless containers, an errno path oracle for black-box target fingerprinting, and three minimal-guessing methods for achieving remote code execution (RCE). These methods include exploiting bash file descriptor 255, Rails schema_cache.yml deserialization, and a Node.js worker path overwrite without requiring a process restart.