webeasy

FAVn

spbctf

Task: LFI vulnerability in favicon loading via URL parameter. Solution: Path traversal using ../ sequences to read arbitrary files including the flag.

$ ls tags/ techniques/
lfi_via_parameterpath_traversal

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Create a free account with GitHub, then upgrade to Pro.

$ssh [email protected]