$ cat writeup.md…
$ cat writeup.md…
hackerlab
Task: a host exposed an OCR web app and SSH, with PHP source later showing OCR text rendered through Twig. Solution: build OCR-friendly Twig payload images for SSTI-to-RCE, extract SSH credentials from image metadata, then abuse SUID cp to add a sudoers rule and read the root flag half.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar