$ cat writeup.md…
$ cat writeup.md…
hackadvisor
Task: PHP web app with XLSX import using PhpSpreadsheet; XmlScanner blocks standard XXE via DOCTYPE/ENTITY regex. Solution: Encode malicious XML (sharedStrings.xml) as UTF-32BE — three null bytes between characters defeat the \\0? regex pattern, while libxml2 auto-detects the encoding and resolves the XXE entity to read /root/flag.txt.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar