webPromedium

Calculator

hackerlab

Task: Calculator web app with Go backend exposing /source endpoint. Solution: Discovered obfuscated 'file' parameter (byte array), exploited LFI to read /proc/self/environ and extract flag from environment variables.

$ ls tags/ techniques/
Local File Inclusion via hidden parameterReading /proc/self/environ for environment variablesDecoding obfuscated Go byte arrays

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Sign in with GitHub to continue. No email required.

$sign in

$ grep --similar

Similar writeups