webProeasy
Portfolio (Red Portfolio)
hackerlab
Task: PHP portfolio application with user profiles stored as files. Solution: Path traversal via username parameter (../../fl4g) to read flag file outside web root.
$ ls tags/ techniques/
Path Traversal via username parameterArbitrary file read through profile mechanism
π
Permission denied (requires tier.pro)
Sign in to access full writeups
Sign in with GitHub to continue. No email required.
$sign in$ grep --similar
Similar writeups
- [web][Pro]ΠΠ°ΠΌΠ΅ΡΠΊΠΈ (Notes)β hackerlab
- [web][Pro]90 - Π‘Π°ΠΌΠΎΠ΅ Π½Π°Π΄Π΅ΠΆΠ½ΠΎΠ΅ Ρ ΡΠ°Π½ΠΈΠ»ΠΈΡΠ΅ (The Most Secure Storage)β duckerz
- [web][Pro]ΠΠ²Π΅Π·Π΄Π½ΡΠΉ ΡΠ΅ΠΉΡ (Star Safe)β hackerlab
- [web][Pro]Π’Π²ΠΎΡΠ΅Π½ΠΈΠ΅ Π±Π΅Π·ΡΠΌΡΠ° (Work of a Madman)β hackerlab
- [web][Pro]ΠΡΠΎΡΠΎΠΊΠΎΠ» \"ΠΠ°ΡΠΌΠ΅Π½ΠΈΠ΅\" (Eclipse Protocol)β hackerlab