↓
Skip to main content
[root@emanuelmairoll.at]#
Posts
Projects
Resume
Posts
Projects
Resume
Polyglot
HITCON 2025 – IMGC0NV
29 August 2025
·
2660 words
·
13 mins
Writeup
CTF
HITCON 2025
Web Security
Python
Pickle
Polyglot
A writeup about exploiting an image converter service through path traversal and multiprocessing pickle deserialization. The solution required crafting a polyglot file that’s both a valid BMP image and a malicious pickle payload to achieve RCE.