webProeasy

Waf

web-kids20

LFI (Local File Inclusion) challenge with WAF bypass. The application has a WAF that filters path traversal sequences (`../`), but the filter can be bypassed using nested sequences.

$ ls tags/ techniques/
lfi_waf_bypassnested_path_traversaldouble_encoding

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Sign in with GitHub to continue. No email required.

$sign in

$ grep --similar

Similar writeups