$ cat writeup.md…
$ cat writeup.md…
hackerlab
Task: a PHP/XML web app on port 18400 parsed attacker-controlled XML with external entities enabled, exposing local files, localhost services, and command execution through expect://. Solution: use XXE to recover source and clues, reverse the custom encoder to get elliot's SSH password, then abuse sudo ab as a root file-read exfiltration primitive.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar