webProeasy

P.S. (ping3)

spbctf

Task: Process monitoring service passes user input to ps command. Solution: WAF allows && operator, use command chaining with PID 1 to read flag.

$ ls tags/ techniques/
waf_bypasscommand_chaining_and

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Sign in with GitHub to continue. No email required.

$sign in

$ grep --similar

Similar writeups

  • [web][Pro]Ping me— spbctf
  • [web][Pro]ls— spbctf
  • [web][Pro]Echo v2— web-kids20
  • [web][Pro]Grep It All— web-kids20
  • [web][Pro]Echo— spbctf