webhard

RootBabyKalmarCTF

kalmarctf

Task: CTFd 3.8.1 instance with admin credentials, flag at /flag2-<random>.txt. Solution: Exploit ZIP import path traversal via uploads// bypass to write .pth file for RCE.

$ ls tags/ techniques/
zip_path_traversal_bypasspth_code_executionjinja2_template_overwrite

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Create a free account with GitHub to get started.

$ssh [email protected]