webmedium

Interstellar Challenge Scenario

Hack The Box

Task: a PHP/MySQL web app with a localhost-only profile edit feature and a server-side communication endpoint. Solution: abuse parser confusion for SSRF to 127.0.0.1, plant a second-order SQLi in the session name, write a PHP webshell with INTO OUTFILE, and read the randomized flag file.

$ ls tags/ techniques/
ssrf_localhost_bypassparser_confusion_abusesecond_order_sqliunion_into_outfilewebshell_drop

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Create a free account with GitHub to get started.

$ssh [email protected]