$ cat writeup.md…
$ cat writeup.md…
hackadvisor
Task: Collaborative documentation platform with a docs viewer that uses PHP include() with unsanitized file parameter, enabling LFI. Flag is stored as an environment variable and in /root/flag.txt (chmod 600). Solution: Chain LFI with Apache access log poisoning — inject PHP webshell via User-Agent header, then include the poisoned log to achieve RCE and read the FLAG environment variable.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar