webmedium

Секрет (Secret)

hackerlab

Task: Web application with hidden functionality. Solution: Fuzz POST parameters to discover hidden cmd parameter, exploit command injection via system() to read flag from source code.

$ ls tags/ techniques/
POST parameter fuzzingCommand Injection via system()PHP source code analysis

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Create a free account with GitHub, then upgrade to Pro.

$ssh [email protected]