webmedium
143 - Личный блог
duckerz
Task: PHP blog application with __VIEWSTATE cookie containing serialized objects. Solution: Found HMAC key in phpinfo(), crafted signed PHP object injection payload with LFI via php://filter to read .env file containing the flag.
$ ls tags/ techniques/
php_object_injectionlfi_exploitationhmac_bypassfilter_wrapper
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Create a free account with GitHub, then upgrade to Pro.
$ssh [email protected]