$ cat writeup.md…
$ cat writeup.md…
hackadvisor
Task: PHP CMS with unsanitized include() on a view parameter, Apache log readable via open_basedir. Solution: LFI via path traversal to read Apache access log, then User-Agent log poisoning with PHP webshell (single quotes!) to achieve RCE and read flag from environment variable.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar