webmedium

Secure Server

hackthebox

Task: Fix vulnerabilities in a PHP web application that was exploited via LFI + log poisoning. Solution: Replace include with readfile, add basename() and regex validation to prevent path traversal.

$ ls tags/ techniques/
lfi_to_rcelog_poisoninginput_validationbasename_sanitization

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Create a free account with GitHub, then upgrade to Pro.

$ssh [email protected]