Hack. Eat. Sleep. Repeat!!!
Ghauri
and got the flag.Ghauri is an sql injection exploitation tool.htbmeetupcmr{5QL_1nj3c710n_M45t3ry}
php
file and it got flagged immediately.php
extensions which worked.Phtml
bypassed the filters.home
directory.ctfuser
and it worked.sudo -l
and I discovered that I can run nmap
as root.gtfobins
./var/www/html/.flag.txt
htbmeetupcmr{Upl04d_R357r1ct10n_Byp455}
email
is vulnerable to server side template injection. I tried payload `` and got 49
.ls
.htbmeetupcmr{Sup3r_S3rv3r_T3mpl4t3_1nj3ct}
Final payload-: ``