$ cat writeup.md…
$ cat writeup.md…
hackerlab
Task: an Apache/PHP Wikipedia viewer exposed a database dump, then trusted a cookie inside a SQL query, leading to blind SQL injection and file reads via LOAD_FILE. Solution: recover source, abuse a hidden admin backdoor for RCE, plant an SSH key through an internal authorized_keys updater, then escalate to root with sudo scp -S.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar