Do more than 1
HardWeb
Overview
This is my secure site. I want you to test it for any vulnerabilities. If it's not secure, retrieve the flag located at `/[randnom]/[randnom]_flag.txt`. Flag Format: Flag{}
Lab Details
Prerequisites & Requirements
- Understanding of web application security principles
- Knowledge of file upload vulnerabilities
- Familiarity with Apache server configuration and .htaccess files
- Basic knowledge of PHP web applications
- Command line skills and Linux file system navigation
What will you learn?
- How to bypass file upload restrictions by manipulating content types
- How Apache server interprets .htaccess files and how they can be exploited
- How to achieve remote code execution through file upload vulnerabilities
- How to leverage the .htaccess file to execute PHP code without having typical PHP files
Tools
- Web browser
- Burp Suite (for intercepting and modifying HTTP requests)
- Basic text editor (for crafting payload files)
Job Positions
Tags
RcePhpUnrestricted File UploadServer MisconfigurationWebshell