webProeasy
DevOps 300k/s
hackerlab
Task: Nginx configuration provided with location/alias off-by-slash misconfiguration. Solution: exploited path traversal via /static../ to read flag.txt outside the intended directory.
$ ls tags/ techniques/
source_code_analysisnginx_alias_path_traversaloff_by_slash_exploitation
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Sign in with GitHub to continue. No email required.
$sign in$ grep --similar
Similar writeups
- [web][Pro]Протокол \"Затмение\" (Eclipse Protocol)— hackerlab
- [web][Pro]Lab 160 — WikiForge — Nginx Alias Path Traversal— hackadvisor
- [web][free]Никто, конечно, не чиллил— alfactf
- [web][Pro]Lab 209 — BuildForge — Path Traversal in Static File Serving— hackadvisor
- [web][Pro]board_of_secrets— miptctf