webProeasy
Магазин (Gadget Shop)
hl_hacker
Task: Web application with shipping cost calculator form. Solution: Command injection via semicolon separator in zip_code parameter, filter bypass using glob wildcard (fl* instead of flag) to read flag.txt.
$ ls tags/ techniques/
Command Injection via semicolon separatorFilter bypass using glob wildcards (fl* instead of flag)Shell command execution through user input
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Sign in with GitHub to continue. No email required.
$sign in$ grep --similar
Similar writeups
- [misc][Pro]Калькулятор— hackerlab
- [web][Pro]Flag Shop— hackerlab
- [web][Pro]156 - Сломанный магазин (Broken Shop)— duckerz
- [pwn][Pro]Хаос на АЗС (Chaos at the Gas Station)— hackerlab
- [web][Pro]B64Decoder— hackerlab