webmedium

XXE filter

spbctf

Task: Web application vulnerable to XXE with flag hardcoded in PHP source code. Solution: Used XXE with php://filter wrapper and base64 encoding to read PHP source code without execution.

$ ls tags/ techniques/
source_code_leakxxe_php_filterbase64_wrapper

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Create a free account with GitHub, then upgrade to Pro.

$ssh [email protected]