webeasy

Файлообменник (File Exchange)

hackerlab

Task: File upload service with extension blacklist and .htaccess available. Solution: Discovered AddType directive in .htaccess that processes .x-httpd-php as PHP; uploaded webshell with this extension to bypass blacklist and achieve RCE.

$ ls tags/ techniques/
.htaccess misconfiguration analysisFile upload filter bypass via custom extensionCustom PHP handler extension abuse

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Create a free account with GitHub, then upgrade to Pro.

$ssh [email protected]