webProeasy

MetricFlow

hackadvisor

Task: Analytics dashboard with DuckDB-powered SQL Data Explorer that passes user queries without restricting callable functions. Solution: Used DuckDB's read_csv_auto() table function to read /root/flag.txt from the server filesystem.

$ ls tags/ techniques/
decoy_flag_avoidanceduckdb_file_read_via_read_csv_autounrestricted_sql_function_access

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Sign in with GitHub to continue. No email required.

$sign in

$ grep --similar

Similar writeups