$ cat writeup.md…
$ cat writeup.md…
hackerlab
Task: A PHP business-card site exposes a localhost-only log viewer that trusts a proxy header and requires Apache's error log. Solution: Spoof localhost, poison the log with PHP, then execute a command through the included log file.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar