webProeasy

Путь к флагу

bug-makers

Task: static nginx site with a flag file protected by Basic Auth; .git directory exposed. Solution: dump git repo to find nginx config with alias off-by-slash misconfiguration, traverse via /images../fourth/flag.txt to bypass auth.

$ ls tags/ techniques/
git_repository_dumpingnginx_alias_traversalauthentication_bypass_via_path_traversal

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Sign in with GitHub to continue. No email required.

$sign in

$ grep --similar

Similar writeups