webPromedium
143 - Личный блог
duckerz
Task: PHP blog application with __VIEWSTATE cookie containing serialized objects. Solution: Found HMAC key in phpinfo(), crafted signed PHP object injection payload with LFI via php://filter to read .env file containing the flag.
$ ls tags/ techniques/
php_object_injectionlfi_exploitationhmac_bypassfilter_wrapper
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Sign in with GitHub to continue. No email required.
$sign in$ grep --similar
Similar writeups
- [web][Pro]Печеньки с молочком (Cookies with Milk)— duckerz
- [web][Pro]76 - Надежное хранилище (Reliable Storage)— duckerz
- [web][Pro]Web-полигон (Web Polygon)— duckerz
- [web][Pro]Скрытая документация (Hidden Documentation)— duckerz
- [crypto][Pro]Хмак! Будь здоров!— duckerz