webeasy

P.S. (ping3)

spbctf

Task: Process monitoring service passes user input to ps command. Solution: WAF allows && operator, use command chaining with PID 1 to read flag.

$ ls tags/ techniques/
waf_bypasscommand_chaining_and

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Create a free account with GitHub, then upgrade to Pro.

$ssh [email protected]