$ cat writeup.md…
$ cat writeup.md…
hackerlab
Task: a fake Google search page on Apache accepted a user-controlled query and passed it into shell_exec(curl ...), leading to command injection. Solution: use $() with base64 exfiltration, recover and abuse a hidden SUID backdoor in a replaced echo binary, then escalate to root through sudo wget file write.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar