webeasy

FlagBox

hackerlab

Task: Bypass str_replace filter to submit the word "hacker". Solution: Use nested string technique where inner occurrences are removed to form the target word after fixed number of filter applications.

$ ls tags/ techniques/
Nested string bypass for str_replace filterBase64 obfuscation analysisSession-dependent filter behavior understanding

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Create a free account with GitHub, then upgrade to Pro.

$ssh [email protected]