miscmedium

138 - Распаковщик (Unpacker)

duckerz

Task: ZIP file upload service that extracts archives. Solution: ZIP symlink attack to achieve LFI, bypassing filename-based filter to read the flag.

$ ls tags/ techniques/
local_file_inclusionzip_symlink_attacksource_code_leakfilter_bypass

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Create a free account with GitHub, then upgrade to Pro.

$ssh [email protected]