$ cat writeup.md…
$ cat writeup.md…
hackerlab
Task: Achieve RCE on a PHP application with LFI via include() with .php extension appended. Solution: Use php://filter/convert.base64-encode to read source code and leak credentials, then use php_filter_chain_generator to craft an iconv filter chain that injects arbitrary PHP code through the LFI without file upload.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar