The Elf Strikes Back!

Web Exploitation - GET ; Upload ; Reverse Shell

Video

Rooms

Upload vulnsarrow-up-right

Intro to Shellsarrow-up-right

Resources

PHP Reverse Shellarrow-up-right

Challenge

Open the site

You have been assigned an ID number for your audit of the system: ODIzODI5MTNiYmYw

http://10.10.236.79/?id=ODIzODI5MTNiYmYw

What string of text needs adding to the URL to get access to the upload page?

circle-check

What type of file is accepted by the site?

circle-check

Bypass the filter and upload a reverse shell.

Change the following parameters in the file

Tried /uploads, /images, /media, /resources

In which directory are the uploaded files stored?

circle-check

Activate your reverse shell and catch it in a netcat listener!

circle-check

What is the flag in /var/www/flag.txt?

circle-check

Last updated