webeasy

Forrest Gump

hackerlab

Task: a PHP password form with a Forrest Gump theme — 'do whatever you're told'. Solution: enter the last word from each response message as the next password across three session-preserved steps: 'пароль' → 'неправильный' → 'позже' to reveal the flag.

$ ls tags/ techniques/
session_state_machine_exploitationword_chain_puzzleresponse_message_as_hint

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Create a free account with GitHub to get started.

$ssh [email protected]