mischard

Лабиринт (Labyrinth)

hackerlab

Task: TCP service with ASCII maze and /hello command that reflects user name via PHP eval() bridge script. Solution: break out of single-quoted string in PHP eval() to inject system() calls, bypass badword blacklist using shell empty-quote concatenation (l''s, c''at, fl''ag).

$ ls tags/ techniques/
php_eval_injectionsingle_quote_breakoutshell_empty_quote_concatenationbadword_bypassraw_socket_exploit

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Create a free account with GitHub to get started.

$ssh [email protected]