miscPromedium

138 - Распаковщик (Unpacker)

duckerz

Task: ZIP file upload service that extracts archives. Solution: ZIP symlink attack to achieve LFI, bypassing filename-based filter to read the flag.

$ ls tags/ techniques/
local_file_inclusionzip_symlink_attacksource_code_leakfilter_bypass

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Sign in with GitHub to continue. No email required.

$sign in

$ grep --similar

Similar writeups