webProhard
Double Shop
srdnlen
Task: Web challenge with Apache reverse proxy fronting Tomcat. Solution: Chained 3 misconfigurations — path traversal to leak credentials, semicolon path confusion to bypass Apache ACL, and RemoteIpValve IP spoofing to access Tomcat Manager.
$ ls tags/ techniques/
path_traversalcredential_leakapacheip_spoofingtomcatreverse_proxypath_confusionremoteipvalvetomcat_managerjsp
apache_tomcat_semicolon_path_confusionpath_traversal_via_receipt_endpointremoteipvalve_ip_spoofingtomcat_manager_access_bypassreverse_proxy_acl_bypass
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Sign in with GitHub to continue. No email required.
$sign in$ grep --similar
Similar writeups
- [web][Pro]Board of Secrets Revenge— miptctf
- [web][Pro]board_of_secrets— miptctf
- [reverse][free]Leftovers— gpnctf2026
- [web][Pro]DecisionForge— hackadvisor
- [web][free]Carabubu— alfactf