webProeasy
MetricFlow
hackadvisor
Task: Analytics dashboard with DuckDB-powered SQL Data Explorer that passes user queries without restricting callable functions. Solution: Used DuckDB's read_csv_auto() table function to read /root/flag.txt from the server filesystem.
$ ls tags/ techniques/
decoy_flag_avoidanceduckdb_file_read_via_read_csv_autounrestricted_sql_function_access
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Sign in with GitHub to continue. No email required.
$sign in$ grep --similar
Similar writeups
- [web][Pro]Lab 168 — MetricFlow — Insecure Deserialization via Dashboard Import— hackadvisor
- [web][Pro]MetricFlow— hackadvisor
- [web][Pro]MetricFlow — DOM XSS via Prototype Pollution Gadget— hackadvisor
- [web][Pro]Lab 112 — MetricFlow — IDOR in Usage Analytics API— hackadvisor
- [web][Pro]Lab 3 — DeskFlow — SQL Injection in Ticket View— hackadvisor