webmedium
90 - Самое надежное хранилище (The Most Secure Storage)
duckerz
Task: Go file storage with JWT authentication. Solution: Mass assignment to set is_paid=true during registration, then path traversal via unsanitized folderName parameter to read flag.txt from root directory.
$ ls tags/ techniques/
mass_assignment_bypasspath_traversal_via_parameterjwt_authentication
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Create a free account with GitHub, then upgrade to Pro.
$ssh [email protected]