webmedium
Pinger
spbctf
Task: Two web apps sharing PHP sessions - Decoder (SQLi) and Pinger (command injection). Solution: Poison session via UNION SQLi to inject malicious uid, then reuse session on Pinger to trigger OS command injection.
$ ls tags/ techniques/
union_sqli_session_poisoningcross_app_session_sharingos_command_injection_semicolon
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Create a free account with GitHub, then upgrade to Pro.
$ssh [email protected]