miscmedium

Hidden Path

hackthebox

Task: Node.js Express app with hidden Unicode character (U+3164 Hangul Filler) in destructuring and array, creating invisible backdoor parameter. Solution: Hex dump analysis to find invisible chars, then POST with choice=6 and URL-encoded invisible parameter for command injection.

$ ls tags/ techniques/
command_injectionunicode_homoglyph_attackhidden_parameter_injection

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Create a free account with GitHub, then upgrade to Pro.

$ssh [email protected]