webeasy

Магазин (Gadget Shop)

hl_hacker

Task: Web application with shipping cost calculator form. Solution: Command injection via semicolon separator in zip_code parameter, filter bypass using glob wildcard (fl* instead of flag) to read flag.txt.

$ ls tags/ techniques/
Command Injection via semicolon separatorFilter bypass using glob wildcards (fl* instead of flag)Shell command execution through user input

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Create a free account with GitHub, then upgrade to Pro.

$ssh [email protected]