$ cat writeup.md…
$ cat writeup.md…
duckerz
Task: PHP blog application with __VIEWSTATE cookie containing serialized objects. Solution: Found HMAC key in phpinfo(), crafted signed PHP object injection payload with LFI via php://filter to read .env file containing the flag.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar