webhard
Minefield
hackerlab
Task: Flask minefield game with balloon parameter. Solution: SSTI in render_template_string() allows RCE via reverse shell to retrieve flag.
$ ls tags/ techniques/
ssti_flaskrender_template_string_injectionblind_rcereverse_shell
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Create a free account with GitHub, then upgrade to Pro.
$ssh [email protected]