$ cat writeup.md…
$ cat writeup.md…
hackerlab (CodeBy Games)
Task: hard multi-stage pentest chain — PHP strcmp() type-juggling auth bypass, file-upload extension/MIME bypass to PHP RCE, sudo command-injection lateral movement, SSH pivot, then ProFTPD 1.3.5 mod_copy (CVE-2015-3306) to read a root-owned file on an internal host. Solution: chain array-parameter auth bypass, md5-rename webshell upload, unquoted-$1 sudo injection to lucas, pivot into 10.2.7.0/24, and SITE CPFR/CPTO to exfiltrate the second flag half.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar