webProeasy

Lab 160 — WikiForge — Nginx Alias Path Traversal

hackadvisor

Task: Knowledge base platform serving static assets via Nginx alias — off-by-slash misconfiguration allows path traversal to read arbitrary files. Solution: Discovered config path from commented JS code, exploited /assets../config/.secrets.json to retrieve the flag.

$ ls tags/ techniques/
source_code_analysisnginx_alias_path_traversaloff_by_slash_exploitationclient_side_hint_discovery

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Sign in with GitHub to continue. No email required.

$sign in

$ grep --similar

Similar writeups