webProeasy

DevOps 300k/s

hackerlab

Task: Nginx configuration provided with location/alias off-by-slash misconfiguration. Solution: exploited path traversal via /static../ to read flag.txt outside the intended directory.

$ ls tags/ techniques/
source_code_analysisnginx_alias_path_traversaloff_by_slash_exploitation

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Sign in with GitHub to continue. No email required.

$sign in

$ grep --similar

Similar writeups