$ cat writeup.md…
$ cat writeup.md…
hackerlab
Task: a static-looking PHP pet-shop site hid Adminer 4.6.2, which could be abused for arbitrary file read through a rogue MySQL LOCAL INFILE server. Solution: exfiltrate local files to uncover a hidden webshell and admin password, then escalate via vulnerable sudoedit and read the root flag before reverting the temporary sudoers change.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar