webeasy
Магазин (Gadget Shop)
hl_hacker
Task: Web application with shipping cost calculator form. Solution: Command injection via semicolon separator in zip_code parameter, filter bypass using glob wildcard (fl* instead of flag) to read flag.txt.
$ ls tags/ techniques/
Command Injection via semicolon separatorFilter bypass using glob wildcards (fl* instead of flag)Shell command execution through user input
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Create a free account with GitHub, then upgrade to Pro.
$ssh [email protected]