webProeasy
Заметки (Notes)
hackerlab
Task: Cloud notes storage with source code provided. Solution: Path Traversal via base64-encoded cookie manipulation - username cookie decoded without path validation allows escaping notes directory to read flag file.
$ ls tags/ techniques/
Path Traversal via cookie manipulationBase64 encoding bypassSource code analysis
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Sign in with GitHub to continue. No email required.
$sign in$ grep --similar
Similar writeups
- [web][Pro]76 - Надежное хранилище (Reliable Storage)— duckerz
- [web][Pro]Та самая заметка (That Same Note)— hackerlab
- [web][Pro]Portfolio (Red Portfolio)— hackerlab
- [web][Pro]B64Decoder— hackerlab
- [web][Pro]Соленый огурец (Salty Pickle)— hackerlab