webhard

Double Shop

srdnlen

Task: Web challenge with Apache reverse proxy fronting Tomcat. Solution: Chained 3 misconfigurations — path traversal to leak credentials, semicolon path confusion to bypass Apache ACL, and RemoteIpValve IP spoofing to access Tomcat Manager.

$ ls tags/ techniques/
apache_tomcat_semicolon_path_confusionpath_traversal_via_receipt_endpointremoteipvalve_ip_spoofingtomcat_manager_access_bypassreverse_proxy_acl_bypass

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Create a free account with GitHub, then upgrade to Pro.

$ssh [email protected]