webPromedium

Commentary

scarlet

Task: find a hidden flag on an nginx web server. Solution: send an HTTP request to port 80 with the task name "commentary" as the Host header, triggering the nginx default page which contains the flag in HTML comments.

$ ls tags/ techniques/
virtual_host_enumerationhost_header_manipulationdefault_page_disclosure

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Sign in with GitHub to continue. No email required.

$sign in

$ grep --similar

Similar writeups