webmedium

Commentary

scarlet

Task: find a hidden flag on an nginx web server. Solution: send an HTTP request to port 80 with the task name "commentary" as the Host header, triggering the nginx default page which contains the flag in HTML comments.

$ ls tags/ techniques/
virtual_host_enumerationhost_header_manipulationdefault_page_disclosure

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Create a free account with GitHub, then upgrade to Pro.

$ssh [email protected]