webhard

Revenge Upload

hackerlab

Task: achieve RCE on a file upload service without source code. Solution: exploit a race condition by uploading a PHP webshell with double extension (.png.php) and requesting it before the server deletes it.

$ ls tags/ techniques/
race_condition_uploaddouble_extension_bypassphp_webshell

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Create a free account with GitHub, then upgrade to Pro.

$ssh [email protected]