webeasy

Художник

hackerlab

Task: a static-looking Apache 2.4.49 website exposed a vulnerable CGI setup consistent with CVE-2021-41773. Solution: use path traversal through /cgi-bin/ to execute /bin/sh, enumerate the filesystem, and grep for the hidden flag file.

$ ls tags/ techniques/
filesystem_enumerationapache_path_traversalcgi_rce

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Create a free account with GitHub to get started.

$ssh [email protected]