webProeasy

Магазин (Gadget Shop)

hl_hacker

Task: Web application with shipping cost calculator form. Solution: Command injection via semicolon separator in zip_code parameter, filter bypass using glob wildcard (fl* instead of flag) to read flag.txt.

$ ls tags/ techniques/
Command Injection via semicolon separatorFilter bypass using glob wildcards (fl* instead of flag)Shell command execution through user input

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Sign in with GitHub to continue. No email required.

$sign in

$ grep --similar

Similar writeups