webProeasy

Grep It All

web-kids20

A "full shell" service at https://2019-10-13-cmdinj.ctf.su/task/grep, but you can only get digits. The service runs user commands but pipes output through `grep -Eo "[0-9]+"` to only show numbers. Flag is in /flag.

$ ls tags/ techniques/
shell_comment_injectionoutput_filter_bypass

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Sign in with GitHub to continue. No email required.

$sign in

$ grep --similar

Similar writeups

  • [web][Pro]Echo v2— web-kids20
  • [web][Pro]ls— spbctf
  • [web][Pro]P.S. (ping3)— spbctf
  • [web][Pro]Ping me— spbctf
  • [web][Pro]Echo— spbctf