miscPromedium
138 - Распаковщик (Unpacker)
duckerz
Task: ZIP file upload service that extracts archives. Solution: ZIP symlink attack to achieve LFI, bypassing filename-based filter to read the flag.
$ ls tags/ techniques/
local_file_inclusionzip_symlink_attacksource_code_leakfilter_bypass
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Sign in with GitHub to continue. No email required.
$sign in$ grep --similar
Similar writeups
- [reverse][Pro]Змеиная магия (Snake Magic)— hackerlab
- [web][Pro]110 - Retro Search (Ретро поиск) - duckerz CTF— duckerz
- [misc][Pro]Игра (Game)— hackerlab
- [forensics][Pro]Странный ZIP-архив (Strange ZIP Archive)— hackerlab
- [web][Pro]143 - Личный блог— duckerz