Posts

Showing posts with the label directory traversal

NahamCon2021 CTF - $Echo - Writeup

Image
Introduction Today we're doing a CTF writeup for the $Echo challenge from the NahamCon2021 CTF. $Echo is a web-based challenge and after we started the challenge we received a URL to interact with: http://challenge.nahamcon.com:32212 After some testing, we find that the web-app repeats alpha-numeric input from the user and outputs it to the page, except: The input may not be longer than 15 characters long, and the string may not include special characters, with a few exceptions. The exempt special characters being forward slash ( / ), periods ( . ), backticks ( ` ), and less-than bracket ( < ). With the backticks, we can break out of the command being issued by the web-app and perform command injection on the web-server. input `ls` We can assume that index.php is the file contains the web-app we're interacting with, but we'll look at that later. For now, let's locate the flag: input `ls ..` The flag is located one directory above our web-root directory. We c...