webProhard

Revenge Upload

hackerlab

Task: achieve RCE on a file upload service without source code. Solution: exploit a race condition by uploading a PHP webshell with double extension (.png.php) and requesting it before the server deletes it.

$ ls tags/ techniques/
race_condition_uploaddouble_extension_bypassphp_webshell

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Sign in with GitHub to continue. No email required.

$sign in

$ grep --similar

Similar writeups